SUSE-IU-2026:6610-1: Security update of suse-sles-15-sp6-chost-byos-v20260827-hvm-ssd-x86_64
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Sat Aug 29 07:04:15 UTC 2026
SUSE Image Update Advisory: suse-sles-15-sp6-chost-byos-v20260827-hvm-ssd-x86_64
-----------------------------------------------------------------
Image Advisory ID : SUSE-IU-2026:6610-1
Image Tags : suse-sles-15-sp6-chost-byos-v20260827-hvm-ssd-x86_64:20260827
Image Release :
Severity : important
Type : security
References : 1158038 1185845 1197231 1239718 1240054 1243603 1246504 1247948
1249435 1252306 1252744 1253043 1253193 1253262 1253740 1254323
1255416 1255451 1256709 1257068 1257383 1257463 1257882 1258069
1258193 1258538 1258718 1259311 1259520 1259706 1259802 1259842
1260296 1260347 1260531 1261256 1261400 1261606 1261900 1261969
1261982 1261983 1262044 1262069 1262070 1262071 1262072 1262098
1262266 1262305 1262319 1262573 1262654 1262745 1262771 1262948
1262993 1263010 1263068 1263083 1263366 1263367 1263656 1263658
1263718 1263772 1263788 1263879 1263880 1263889 1264013 1264053
1264076 1264076 1264089 1264090 1264116 1264137 1264145 1264263
1264470 1264484 1264558 1264610 1264721 1264779 1264795 1264962
1265170 1265211 1265221 1265223 1265267 1265268 1265308 1265410
1265413 1265421 1265450 1265579 1265591 1265592 1265593 1265594
1265596 1265794 1265935 1265938 1266039 1266214 1266238 1266290
1266304 1266350 1266640 1266758 1266767 1266798 1266799 1266800
1266801 1266802 1266810 1266827 1266850 1266890 1266913 1267189
1267212 1267214 1267361 1267365 1267369 1267375 1267381 1267384
1267387 1267388 1267389 1267422 1267426 1267435 1267494 1267531
1267567 1267581 1267584 1267591 1267596 1267618 1267621 1267635
1267640 1267644 1267647 1267651 1267652 1267656 1267663 1267682
1267682 1267684 1267697 1267715 1267722 1267821 1267874 1267918
1267966 1267993 1267995 1268012 1268013 1268017 1268022 1268029
1268049 1268131 1268162 1268237 1268275 1268290 1268307 1268307
1268322 1268335 1268349 1268375 1268402 1268407 1268409 1268413
1268415 1268416 1268417 1268420 1268422 1268427 1268660 1268683
1268886 1268896 1268977 1268989 1269022 1269033 1269036 1269066
1269090 1269100 1269159 1269172 1269174 1269181 1269184 1269188
1269193 1269195 1269279 1269289 1269310 1269314 1269383 1269398
1269489 1269493 1269512 1269513 1269574 1269577 1269583 1269584
1269622 1269623 1269633 1269678 1269681 1269773 1269788 1269790
1269795 1269798 1269808 1269821 1269884 1269959 1269981 1269986
1269988 1269993 1269997 1270000 1270008 1270009 1270010 1270016
1270018 1270021 1270022 1270059 1270208 1270230 1270257 1270393
1270515 1270620 1270706 1270772 1270801 1270936 1270994 1271044
1271046 1271048 1271049 1271050 1271052 1271053 1271054 1271055
1271183 1271192 1271193 1271194 1271195 1271234 1271349 1271351
1271352 1271354 1271366 1271368 1271372 1271469 1271526 1271528
1271530 1271531 1271532 1271533 1271534 1271535 1271536 1271537
1271538 1271539 1271672 1271673 1271674 1271675 1271676 1271677
1271684 1271712 1271712 1271825 1271866 1271899 1271904 1271908
1271910 1271912 1271947 1271964 1271980 1271982 1271983 1271984
1271986 1271987 1271988 1271989 1271990 1272164 1272165 1272166
1272167 1272168 1272169 1272171 1272176 1272180 1272183 1272207
1272242 1272263 1272268 1272282 1272414 1272466 1272468 1272554
1272573 1272607 1272665 1272678 1272693 1272694 1272836 1272855
1272865 1272904 1272907 1272918 1273004 1273035 1273231 1274072
1274432 1274627 1275011 1275012 1275013 1275014 1275015 1275016
1275017 1275018 CVE-2023-2058 CVE-2024-58251 CVE-2025-10263 CVE-2025-31133
CVE-2025-52565 CVE-2025-54518 CVE-2025-59529 CVE-2025-68324 CVE-2026-0864
CVE-2026-10536 CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11622
CVE-2026-11721 CVE-2026-11822 CVE-2026-11824 CVE-2026-11850 CVE-2026-11940
CVE-2026-11972 CVE-2026-11979 CVE-2026-12064 CVE-2026-12087 CVE-2026-12505
CVE-2026-12617 CVE-2026-13204 CVE-2026-13321 CVE-2026-13595 CVE-2026-1502
CVE-2026-15308 CVE-2026-15779 CVE-2026-15816 CVE-2026-23392 CVE-2026-25707
CVE-2026-27456 CVE-2026-3039 CVE-2026-31431 CVE-2026-31482 CVE-2026-31483
CVE-2026-31500 CVE-2026-31542 CVE-2026-31598 CVE-2026-31628 CVE-2026-31697
CVE-2026-31698 CVE-2026-31699 CVE-2026-31759 CVE-2026-31759 CVE-2026-31771
CVE-2026-32316 CVE-2026-3276 CVE-2026-3276 CVE-2026-33186 CVE-2026-33814
CVE-2026-33814 CVE-2026-33947 CVE-2026-34986 CVE-2026-34986 CVE-2026-35469
CVE-2026-3592 CVE-2026-3593 CVE-2026-39821 CVE-2026-39821 CVE-2026-39956
CVE-2026-39979 CVE-2026-40164 CVE-2026-40226 CVE-2026-40355 CVE-2026-40356
CVE-2026-40467 CVE-2026-40468 CVE-2026-40553 CVE-2026-41579 CVE-2026-41676
CVE-2026-41677 CVE-2026-41678 CVE-2026-41681 CVE-2026-41898 CVE-2026-41991
CVE-2026-41992 CVE-2026-42327 CVE-2026-42493 CVE-2026-42494 CVE-2026-42495
CVE-2026-42767 CVE-2026-43023 CVE-2026-43033 CVE-2026-43046 CVE-2026-43056
CVE-2026-43074 CVE-2026-43077 CVE-2026-43109 CVE-2026-43198 CVE-2026-43276
CVE-2026-43440 CVE-2026-43475 CVE-2026-4360 CVE-2026-44431 CVE-2026-44605
CVE-2026-44662 CVE-2026-44932 CVE-2026-44933 CVE-2026-44941 CVE-2026-44942
CVE-2026-45409 CVE-2026-45784 CVE-2026-45878 CVE-2026-45886 CVE-2026-45904
CVE-2026-45932 CVE-2026-45984 CVE-2026-46037 CVE-2026-46052 CVE-2026-46056
CVE-2026-46071 CVE-2026-46076 CVE-2026-46080 CVE-2026-46084 CVE-2026-46090
CVE-2026-46109 CVE-2026-46116 CVE-2026-46117 CVE-2026-46120 CVE-2026-46123
CVE-2026-46126 CVE-2026-46144 CVE-2026-46145 CVE-2026-46150 CVE-2026-46159
CVE-2026-46173 CVE-2026-46174 CVE-2026-46193 CVE-2026-46197 CVE-2026-46209
CVE-2026-46227 CVE-2026-46229 CVE-2026-46242 CVE-2026-46243 CVE-2026-46253
CVE-2026-46266 CVE-2026-46273 CVE-2026-46274 CVE-2026-46289 CVE-2026-46319
CVE-2026-46320 CVE-2026-46323 CVE-2026-46324 CVE-2026-46330 CVE-2026-46331
CVE-2026-46333 CVE-2026-4786 CVE-2026-48522 CVE-2026-48523 CVE-2026-48524
CVE-2026-48525 CVE-2026-48526 CVE-2026-48863 CVE-2026-52909 CVE-2026-52918
CVE-2026-52923 CVE-2026-52924 CVE-2026-52933 CVE-2026-52943 CVE-2026-52955
CVE-2026-52956 CVE-2026-52958 CVE-2026-52967 CVE-2026-52969 CVE-2026-52972
CVE-2026-52986 CVE-2026-52993 CVE-2026-53016 CVE-2026-53041 CVE-2026-53050
CVE-2026-53052 CVE-2026-53053 CVE-2026-53071 CVE-2026-53072 CVE-2026-53129
CVE-2026-53131 CVE-2026-53133 CVE-2026-53177 CVE-2026-53178 CVE-2026-53182
CVE-2026-53196 CVE-2026-53224 CVE-2026-53246 CVE-2026-53250 CVE-2026-53253
CVE-2026-53256 CVE-2026-53262 CVE-2026-53267 CVE-2026-53297 CVE-2026-53324
CVE-2026-53354 CVE-2026-53357 CVE-2026-53359 CVE-2026-53362 CVE-2026-53366
CVE-2026-53375 CVE-2026-53388 CVE-2026-53391 CVE-2026-53402 CVE-2026-53612
CVE-2026-53613 CVE-2026-53614 CVE-2026-5435 CVE-2026-54411 CVE-2026-5704
CVE-2026-57062 CVE-2026-57432 CVE-2026-58010 CVE-2026-58011 CVE-2026-58012
CVE-2026-58013 CVE-2026-58014 CVE-2026-58016 CVE-2026-58055 CVE-2026-58216
CVE-2026-58218 CVE-2026-58221 CVE-2026-58222 CVE-2026-58224 CVE-2026-5946
CVE-2026-5950 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846
CVE-2026-59847 CVE-2026-59848 CVE-2026-59850 CVE-2026-59856 CVE-2026-59857
CVE-2026-59858 CVE-2026-59995 CVE-2026-59996 CVE-2026-59997 CVE-2026-59998
CVE-2026-59999 CVE-2026-60000 CVE-2026-60001 CVE-2026-60002 CVE-2026-6019
CVE-2026-6019 CVE-2026-6100 CVE-2026-61548 CVE-2026-6238 CVE-2026-62423
CVE-2026-62424 CVE-2026-62425 CVE-2026-62426 CVE-2026-62427 CVE-2026-62428
CVE-2026-62429 CVE-2026-62430 CVE-2026-62431 CVE-2026-62432 CVE-2026-62433
CVE-2026-62434 CVE-2026-63794 CVE-2026-63802 CVE-2026-63806 CVE-2026-63807
CVE-2026-63824 CVE-2026-63826 CVE-2026-63829 CVE-2026-63884 CVE-2026-63893
CVE-2026-63912 CVE-2026-63917 CVE-2026-63919 CVE-2026-63921 CVE-2026-63922
CVE-2026-63924 CVE-2026-63946 CVE-2026-63952 CVE-2026-63968 CVE-2026-63971
CVE-2026-63975 CVE-2026-63984 CVE-2026-63994 CVE-2026-64106 CVE-2026-64189
CVE-2026-64530 CVE-2026-64560 CVE-2026-64561 CVE-2026-64564 CVE-2026-64600
CVE-2026-6893 CVE-2026-6949 CVE-2026-71401 CVE-2026-71402 CVE-2026-7210
CVE-2026-73070 CVE-2026-73071 CVE-2026-73072 CVE-2026-73074 CVE-2026-73075
CVE-2026-73076 CVE-2026-73077 CVE-2026-73078 CVE-2026-7774 CVE-2026-8286
CVE-2026-8328 CVE-2026-8376 CVE-2026-8458 CVE-2026-8924 CVE-2026-8927
CVE-2026-9079 CVE-2026-9080 CVE-2026-9149 CVE-2026-9150 CVE-2026-9375
CVE-2026-9545 CVE-2026-9547
-----------------------------------------------------------------
The container suse-sles-15-sp6-chost-byos-v20260827-hvm-ssd-x86_64 was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2486-1
Released: Mon Jun 22 14:07:07 2026
Summary: Security update for python-urllib3
Type: security
Severity: important
References: 1265267,CVE-2026-44431
This update for python-urllib3 fixes the following issue
- CVE-2026-44431: sensitive information disclosure due to sensitive headers being forwarded across origins in proxied
low-level redirects (bsc#1265267).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2528-1
Released: Tue Jun 23 11:06:07 2026
Summary: Security update for sqlite3
Type: security
Severity: important
References: 1268012,1268013,CVE-2026-11822,CVE-2026-11824
This update for sqlite3 fixes the following issues
Update to 3.53.2:
- CVE-2026-11822: memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause
process crashes, memory exhaustion, or arbitrary code execution (bsc#1268012).
- CVE-2026-11824: heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers
to cause a crash or execute arbitrary code (bsc#1268013).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2590-1
Released: Tue Jun 23 16:09:07 2026
Summary: Security update for libsolv, libzypp, zypper
Type: security
Severity: important
References: 1158038,1239718,1246504,1247948,1249435,1252744,1253193,1253740,1257068,1257882,1258193,1259311,1259706,1259802,1259842,1265223,1265935,1265938,1266039,1267426,1267874,CVE-2026-25707,CVE-2026-44933,CVE-2026-44941,CVE-2026-44942,CVE-2026-48863,CVE-2026-9149,CVE-2026-9150
This update for libsolv, libzypp, zypper fixes the following issues
- CVE-2026-9149: Heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted .solv file
(bsc#1265935).
- CVE-2026-9150: Stack-based buffer overflow in libsolv's Debian metadata parser when handling SHA384/SHA512 checksums
(bsc#1265938).
- CVE-2026-25707: Handcrafted repo metadata may cause arbitrary local files to be overwritten (bsc#1259802).
- CVE-2026-44933: scan of the Mandatory signature verification plugin support (bsc#1265223).
- CVE-2026-44941: path traversal via 'keyhint' (bsc#1267426).
- CVE-2026-44942: .repo files can have an optional path which can lead to path traversal attacks (bsc#1267874).
- CVE-2026-48863: Fix buffer overflow when parsing EdDSA signature (bsc#1266039).
Changes in libzypp:
Updated to version 17.38.13 (35):
- A .repo files 'path=' entry must not refer to a location
outside the repo (bsc#1267874, CVE-2026-44942)
A 'path=' entry may solely denote a sub-directory of the baseurl
where the metadata are located. A relative path trying to access
data outside the baseurl is reported and sanitized.
- Fix potential crash on malformed or malicious repository
metadata (fixes #740)
- Repo metadata: discard entries referring to a location outside
the repo (bsc#1259802, CVE-2026-25707)
Mirroring those data locally would refer to a location outside
the repo's local cache directory. Those data entries are reported
and discarded.
- zypp.conf: Allow [env] section to add environment variables.
This feature is designed to enable environment-specific settings
or debugging options over an extended period. See zypp.conf(5).
- Prevent configured scripts from escaping the sigcheck directory
(bsc#1265223, CVE-2026-44933)
- StringV: guard hasPrefix/hasPrefixCI against reading past the
view end (fixes #735)
- Mandatory signature verification plugin support (PED#11922)
- Fix purge-kernel -rc kernel handling (bsc#1239718)
- Explicitly_set_pool_DISTTYPE_RPM (fixes #726)
- Check for trusted key updates when updating the general keyring
(bsc#1259706)
- Support multiple MirroredOrigin authorities (bsc#1253193)
- Workaround doxygen bug: doxygen/doxygen#12057
- libzypp.spec: Add missing graphviz-gd BuildRequires (boo#1259842)
- Fix preloader not caching packages from arch specific subrepos
(bsc#1253740)
- Deprioritize invalid mirrors (fixes openSUSE/zypper#636)
- Fix Product::referencePackage lookup (bsc#1259311)
Use a provided autoproduct() as hint to the package name of the
release package. It might be that not just multiple versions of
the same release package provide the same product version, but
also different release packages.
- specfile: on fedora use %{_prefix}/share as zyppconfdir if
%{_distconfdir} is undefined (fixes #693)
This will set '-DZYPPCONFDIR=%{zyppconfdir}' for cmake.
- Fall back to a writable location when precaching packages
without root (bsc#1247948)
- Prepare a legacy /etc/zypp/zypp.conf to be installed on old distros.
See the ZYPP.CONF(5) man page for details.
- Fix runtime check for broken rpm --runposttrans (bsc#1257068)
- Avoid libcurl-mini4 when building as it does not support ftp
protocol.
- Translation: updated .pot file.
- zypp.conf: follow the UAPI configuration file specification
(PED-14658)
In short terms it means we will no longer ship an
/etc/zypp/zypp.conf, but store our own defaults in
/usr/etc/zypp/zypp.conf. The systems administrator may choose to
keep a full copy in /etc/zypp/zypp.conf ignoring our config file
settings completely, or - the preferred way - to overwrite
specific settings via /etc/zypp/zypp.conf.d/*.conf overlay files.
See the ZYPP.CONF(5) man page for details.
- cmake: correctly detect rpm6 (fixes #689)
- Use 'zypp.tmp' as temp directory component to ease setting up
SELinux policies (bsc#1249435)
- zyppng: Update Provider to current MediaCurl2 download
approach, drop Metalink ( fixes #682 )
Changes in libsolv:
Updated to version 0.7.39:
- fix solv_chksum_free segfault when called with a NULL pointer
- made repo_add_solv more robust against corrupt files
[bsc#1265935] [CVE-2026-9149]
- fix potential buffer overflow when verifying EdDSA signatures
[bsc#1266039] [CVE-2026-48863]
- added limit checks in multiple places to catch overflows
- reduce the size of the language id cache
- fixed Debian canon selection
- fixed dbpath detection in repo_rpmdb_librpm
- reduced stack usage in repo page compression (needed for musl)
- fix parsing of sha512 checksums in debian repositories
[bsc#1265938] [CVE-2026-9150]
- improve speed of dirpool_add_dir makeing parsing of filelists.xml
twice as fast
- fix parsing of recommends in the old Mandriva synthesis format
- respect the 'default' attribute in environment optionlist in
the comps parser
- support suse namespace deps in boolean dependencies [bsc#1258193]
- support for the Elbrus2000 (e2k) architecture
- support language() suse namespace rewriting
Changes in zypper:
Update to version 1.14.98:
- Transactional systems: Delegate rw-commands to
transactional-wrapper if available (jsc#PED-13680, jsc#PED-15607)
On a transactional system where the root filesystem is mounted
read-only, zypper commands that modify the system cannot be
executed directly.
If the system provides a transactional-wrapper utility, zypper
will automatically attempt to invoke it. The wrapper
transparently executes the zypper command within a new, writable
snapshot and manages the lifecycle of that snapshot based on the
command's exit status.
On transactional systems lacking a transactional-wrapper, users
must manually invoke specialized tools -such as
transactional-update- to install, update, or remove software.
- Add --filter-version-change to zypper lu.
Adds filtering by version change significance to reduce noise in
update listings. Supports levels: rebuild (hides rebuild-only
changes) and package (hides all release-only changes).
- Autorefresh ris-services the way as plugin-services (bsc#1246504)
It's actually wrong to treat service refreshes different
depending on the service type. For the purpose of a service it
makes no difference how the data about the repos to use are
acquired.
- Report download progress for command line rpms (fixes #613)
- Hint to '-vv ref' to see the mirrors used to download the
metadata (bsc#1257882)
- Service: Allow 'zypper ls SERVICE ...' to test whether a
service with this alias is defined (bsc#1252744)
The command prints an abstract of all services passed on the
command line. It returns 3-ZYPPER_EXIT_ERR_INVALID_ARGS if some
argument does not name an existing service.
- Keep repo data when updating the service settings (bsc#1252744)
- info: Enhance pattern content table (bsc#1158038)
Alternatives (multiple packages providing the same requirement)
are now listed as a single entry in the content table. The entry
shows either the installed package which satisfies the
requirement or the requirement itself as type 'Provides'.
Listing all potential alternatives was miss leading, especially
if the alternatives were mutual exclusive. It looked like an
installed pattern had not-installed requirements and it was not
possible to install all requirements at the same time.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2626-1
Released: Thu Jun 25 10:10:54 2026
Summary: Security update for python-PyJWT
Type: security
Severity: important
References: 1266798,1266799,1266800,1266801,1266802,CVE-2026-48522,CVE-2026-48523,CVE-2026-48524,CVE-2026-48525,CVE-2026-48526
This update for python-PyJWT fixes the following issues
- CVE-2026-48522: `PyJWKClient` passes URI arguments directly to `urllib.request.urlopen()` and allows for SSRF and
token forgery (bsc#1266798).
- CVE-2026-48523: verifier-side algorithm allow-list bypass when `jwt.decode()` or `jwt.decode_complete()` are called
with a PyJWK key (bsc#1266799).
- CVE-2026-48524: unlimited processing of JWTs with unknown kid values by `PyJWKClient.get_signing_key()` leads to
unbounded JWKS endpoint requests and DoS (bsc#1266800).
- CVE-2026-48525: unbounded Base64URL decoding of unused payload segment in `b64=false` detached JWS allows for DoS
(bsc#1266801).
- CVE-2026-48526: no validation of use of JSON Web Keys in HMAC algorithm when decoding JSON Web Tokens allows for
forged HS256 tokens (bsc#1266802).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2632-1
Released: Thu Jun 25 14:35:58 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1255416,1258538,1260531,1261256,1262993,1263879,1263880,1264076,1264116,1264137,1264145,1264263,1264470,1264610,1265170,1265211,1265579,1266214,1266290,1266767,1266810,1266827,1267214,1267361,1267381,1267387,1267388,1267531,1267621,1267640,1267651,1267652,1267663,1267682,1267697,1268307,CVE-2025-10263,CVE-2025-68324,CVE-2026-23392,CVE-2026-31500,CVE-2026-31697,CVE-2026-31698,CVE-2026-31699,CVE-2026-31759,CVE-2026-31771,CVE-2026-43023,CVE-2026-43074,CVE-2026-43077,CVE-2026-43198,CVE-2026-45878,CVE-2026-45886,CVE-2026-45932,CVE-2026-45984,CVE-2026-46037,CVE-2026-46090,CVE-2026-46120,CVE-2026-46123,CVE-2026-46150,CVE-2026-46159,CVE-2026-46197,CVE-2026-46209,CVE-2026-46227,CVE-2026-46273
The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues
The following security issues were fixed:
- CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290).
- CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416).
- CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531).
- CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993).
- CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116).
- CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880).
- CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879).
- CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076).
- CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145).
- CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137).
- CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263).
- CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470).
- CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610).
- CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767).
- CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810).
- CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827).
- CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214).
- CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361).
- CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531).
- CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640).
- CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621).
- CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387).
- CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652).
- CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381).
- CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663).
- CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697).
- CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651).
The following non security issues were fixed:
- bnxt_en: Fix NULL pointer dereference (bsc#1268307).
- Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git-fixes).
- ethtool: provide customized dim profile management (bsc#1261256).
- hv: utils: handle and propagate errors in kvp_register (git-fixes).
- hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes).
- linux/dim: move useful macros to .h file (bsc#1261256).
- net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256).
- net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256).
- net: mana: Add support for RX CQE Coalescing (bsc#1261256).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2639-1
Released: Fri Jun 26 09:04:53 2026
Summary: Security update for containerd
Type: security
Severity: important
References: 1260296,1262948,1265794,1266640,CVE-2026-33186,CVE-2026-33814,CVE-2026-34986,CVE-2026-39821
This update for containerd fixes the following issues
- CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo-
header (bsc#1260296).
- CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE
(bsc#1265794).
- CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of
service (bsc#1262948).
- CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation
bypass and privilege escalation (bsc#1266640).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2676-1
Released: Mon Jun 29 11:53:47 2026
Summary: Security update for bind
Type: security
Severity: important
References: 1265591,1265592,1265593,1265594,1265596,CVE-2026-3039,CVE-2026-3592,CVE-2026-3593,CVE-2026-5946,CVE-2026-5950
This update for bind fixes the following issues
- CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591).
- CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592).
- CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594).
- CVE-2026-5950: Unbounded resend loop in BIND 9 resolver (bsc#1265596).
- CVE-2026-3593: Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation (bsc#1265593).
Changes for bind:
- Update to release 9.18.49
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2699-1
Released: Tue Jun 30 11:19:23 2026
Summary: Security update for cifs-utils
Type: security
Severity: important
References: 1267389,CVE-2026-12505
This update for cifs-utils fixes the following issue
- CVE-2026-12505: cifs.upcall local privilege escalation via request_key-controlled namespace switch and NSS loading
(bsc#1267389).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2714-1
Released: Tue Jun 30 14:02:53 2026
Summary: Security update for tar
Type: security
Severity: important
References: 1261900,1265450,1267189,CVE-2026-5704
This update for tar fixes the following issues
Security fixes:
- CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900).
Other fixes:
- Fix tar changing dir permissions temporarily even when using --no-overwrite-dir.
- Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450).
- Fix extraction failure for paths like 'a/./b' caused by the gnulib openat2
implementation (bsc#1267189).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2736-1
Released: Fri Jul 3 08:00:55 2026
Summary: Recommended update for cloud-init
Type: recommended
Severity: important
References: 1267422
This update for cloud-init fixes the following issues:
- Fix: Cloud init failures observed [ thread::1hcnhpN0LIaV02LMM-IqGis:: ] (bsc#1267422)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2803-1
Released: Wed Jul 8 21:31:25 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1268322,CVE-2026-6893
This update for dracut fixes the following issue
- CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322).
Changes for dracut:
- Update to version 059+suse.565.g682306ec5:
* fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893)
* fix(network-legacy): add input validation to RFC 3442 route parser
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2828-1
Released: Thu Jul 9 20:30:03 2026
Summary: Security update for python-idna
Type: security
Severity: moderate
References: 1265413,CVE-2026-45409
This update for python-idna fixes the following issue
- CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2836-1
Released: Fri Jul 10 08:27:12 2026
Summary: Recommended update for sysconfig
Type: recommended
Severity: moderate
References: 1263889
This update for sysconfig fixes the following issues:
- Update to version 0.85.11:
* netconfig: Do not remove custom /etc/{resolv,yp}.conf on uninstall
of sysconfig-netconfig, but only the symlinks to /run/netconfig
files created by netconfig or tmpfiles.d(5) (bsc#1263889).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2848-1
Released: Fri Jul 10 13:38:57 2026
Summary: Security update for krb5, krb5-mini
Type: security
Severity: important
References: 1263366,1263367,1268131,CVE-2026-11850,CVE-2026-40355,CVE-2026-40356
This update for krb5, krb5-mini fixes the following issues
- CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of-bounds read (bsc#1268131).
- CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366).
- CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2926-1
Released: Mon Jul 13 19:55:06 2026
Summary: Security update for curl
Type: security
Severity: important
References: 1268402,1268407,1268409,1268413,1268415,1268416,1268417,1268420,1268422,1268427,CVE-2026-10536,CVE-2026-12064,CVE-2026-8286,CVE-2026-8458,CVE-2026-8924,CVE-2026-8927,CVE-2026-9079,CVE-2026-9080,CVE-2026-9545,CVE-2026-9547
This update for curl fixes the following issues
- CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402).
- CVE-2026-8458: wrong reuse for different services (bsc#1268407).
- CVE-2026-8924: traling dot domain super cookie (bsc#1268409).
- CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413).
- CVE-2026-9079: stale proxy password leak (bsc#1268415).
- CVE-2026-9080: UAF after pause in socket callback (bsc#1268416).
- CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417).
- CVE-2026-9547: SSH improper host validation (bsc#1268420).
- CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422).
- CVE-2026-12064: proto-default skips SSH verification (bsc#1268427).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:2951-1
Released: Tue Jul 14 11:32:32 2026
Summary: Recommended update for dmidecode
Type: recommended
Severity: moderate
References:
This update for dmidecode fixes the following issues:
- Update to upstream version 3.7 (jsc#PED-16217):
* Support for SMBIOS 3.8.0. This includes a new processor family.
* Support for SMBIOS 3.9.0. This includes chassis type name
adjustments, new rack attributes, slot ID for more slot types,
and new memory device form factors and types.
* Decode HPE OEM records 193, 195, 202, 211, 226, 229, 232 and 244.
* Update HPE OEM records 203, 216, 242 and 245.
* EDSFF slot names now include their .S/.L suffix.
- Preserve the use of term 'BIOS' to avoid breaking customer scripts.
- Preserve the use of non-binary units to avoid breaking customer scripts.
- Drop legacy 'Provides:' and 'Obsoletes:' tags.
The split from the pmtools package happened 15 years ago so they are no longer relevant.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:2983-1
Released: Tue Jul 14 15:19:38 2026
Summary: Security update for jq
Type: security
Severity: moderate
References: 1262044,1262069,1262070,1262071,1262072,CVE-2026-32316,CVE-2026-33947,CVE-2026-39956,CVE-2026-39979,CVE-2026-40164
This update for jq fixes the following issues:
- CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can
lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044).
- CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to
excessive resource consumption when processing crafted JSON input (bsc#1262069).
- CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when
evaluating untrusted jq filters against a release build (bsc#1262070).
- CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an
out-of-bounds read when processing malformed JSON (bsc#1262071).
- CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre-computation of key collisions and can lead to a
denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3004-1
Released: Wed Jul 15 09:26:06 2026
Summary: Security update for openssl-3
Type: security
Severity: moderate
References: 1266350,CVE-2026-42767
This update for openssl-3 fixes the following issue
- CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3015-1
Released: Wed Jul 15 11:07:54 2026
Summary: Recommended update for suseconnect-ng
Type: recommended
Severity: moderate
References: 1197231,1263772,1265410,1268017
This update for suseconnect-ng fixes the following issues:
- Update version to 1.22.1:
- Allow clients to disable the token handling mechanism
- Ensure updated system certs are included when creating HTTP client
connections (bsc#1268017, jsc#SCC-804)
- Update version to 1.22:
- Fix keepalive service failing on unregistered system (bsc#1263772)
- Add collector support for gathering RKE2 & K3s kubernetes provider
info if enabled on a system
- Add email address validation to SUSEConnect -e/--email option. (bsc#1197231)
- Add collector support for detecting if system is running pacemaker
- Avoid double slash at start of request URL path component
- Use product identifier when finding product packages during
migrations (bsc#1265410)
- Add opt in/out support for collectors
- Update config parser for suseconnect to be YAML based
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3026-1
Released: Wed Jul 15 11:49:35 2026
Summary: Security update for python-cryptography
Type: security
Severity: important
References: 1270208,1270515,1270620,1270706,1270772,1270801,1270936,1270994,CVE-2026-41676,CVE-2026-41677,CVE-2026-41678,CVE-2026-41681,CVE-2026-41898,CVE-2026-42327,CVE-2026-44662,CVE-2026-45784
This update for python-cryptography fixes the following issues
- CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1
(bsc#1270208).
- CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-
openssl crate (bsc#1270620).
- CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust-openssl crate (bsc#1270706).
- CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate
(bsc#1270772).
- CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent
memory in rust-openssl crate (bsc#1270801).
- CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate
(bsc#1270515).
- CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key-wrap-with-padding in rust-openssl crate
(bsc#1270936).
- CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-
openssl crate (bsc#1270994).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3030-1
Released: Wed Jul 15 11:53:06 2026
Summary: Security update for glibc
Type: security
Severity: moderate
References: 1263656,1263658,CVE-2026-5435,CVE-2026-6238
This update for glibc fixes the following issues
- CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out-of-bounds write (bsc#1263656).
- CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure
(bsc#1263658).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3051-1
Released: Wed Jul 15 15:10:27 2026
Summary: Security update for runc
Type: security
Severity: important
References:
This update for runc rebuilds it against the current go security release.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3052-1
Released: Wed Jul 15 15:11:55 2026
Summary: Security update for containerd
Type: security
Severity: important
References:
This update for containerd rebuilds it against the current go security release.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3077-1
Released: Thu Jul 16 17:53:44 2026
Summary: Security update for rpcbind
Type: security
Severity: moderate
References: 1267212
This update for rpcbind fixes the following issue
- Fix several memory leaks and buffer overflow (bsc#1267212).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3081-1
Released: Thu Jul 16 17:57:17 2026
Summary: Recommended update for supportutils
Type: recommended
Severity: moderate
References: 1256709,1257383,1258069,1259520
This update for supportutils fixes the following issues:
- Changes to version 3.2.14:
* Integrates supportutils-scrub for data obfuscation, use -j (PED-7324, bsc#1259520)
* Santize env.txt
* ha.txt: Collect hacluster passwd entry
* Added systemd cat unit.service output
* Added softirqs to proc (bsc#1258069)
* Check for /usr/lib/pam.d
* Ignore deprecated crash variable message
* Update supportconfig with note about bpftool
* Added /boot/grub2/grubenv (bsc#1257383)
* Verify procps pkg
- scplugin.rc is restored in package 3.2.12.1 for continued compatibility.
There is no furture development for scplugin.rc. Use supportconfig.rc.
Package version 3.2.12.2 does not have scplugin.rc. (bsc#1256709)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3096-1
Released: Fri Jul 17 13:38:59 2026
Summary: Security update for libxml2
Type: security
Severity: important
References: 1269790,CVE-2026-11979
This update for libxml2 fixes the following issue
- CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3104-1
Released: Fri Jul 17 15:31:14 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1261969,1262098,1262319,1262654,CVE-2026-1502,CVE-2026-4786,CVE-2026-6019,CVE-2026-6100
This update for python311 fixes the following issues
- CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969).
- CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the
`webbrowser.open()` API (bsc#1262319).
- CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654).
- CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the
decompression instance is re-used (bsc#1262098).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3106-1
Released: Fri Jul 17 16:02:05 2026
Summary: Recommended update for kmod
Type: recommended
Severity: moderate
References:
This update for kmod fixes the following issues:
- Use in-kernel decompression if available (jsc#PED-16303):
* libkmod:
+ Add a separate function to load the file contents when it's needed.
When it's not needed on the path of loading modules via finit_module(),
there is no need to mmap the file.
+ Extract 2 functions to handle finit_module vs init_modules differences,
with a fallback from the former to the latter.
+ Don't only set the type as direct, but also keep track of the compression being used.
+ When creating the context, read /sys/kernel/compression to check.
what's the compression type supported by the kernel.
+ Use kernel decompression when available
+ add fallback MODULE_INIT_COMPRESSED_FILE define
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3107-1
Released: Fri Jul 17 16:03:04 2026
Summary: Recommended update for bind
Type: recommended
Severity: moderate
References: 1268896
This update for bind fixes the following issues:
- Force python3.11 for integration tests (bsc#1268896)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3118-1
Released: Fri Jul 17 22:18:41 2026
Summary: Recommended update for gcc15
Type: recommended
Severity: moderate
References: 1252306,1253043,1257463
This update for gcc15 fixes the following issues:
- Update to GCC 15.3 release
- Drop -fhardened from RPM_OPT_FLAGS
- Avoid conflicts between %gcc_libc_bootstrap packages of different
versions if update-alternatives are still in use (SLE 15 and older)
- Allow conversions to/from uint32_t. Filter out -Wtime_t-conversion
from flags to build D target library files. [jsc#PED-15601]
- Remove loongarch64 from quadmath_arch. On LoongArch long double
is IEEE quad, so libquadmath is not needed and no longer built.
- includes fix for bogus expression simplification [bsc#1257463]
even when not available at build time. [bsc#1253043]
- Backport fix that cures a miscompile of libgo on arm. [bsc#1252306]
- Check availability of builtins at expand time
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3141-1
Released: Tue Jul 21 09:04:39 2026
Summary: Recommended update for shadow
Type: recommended
Severity: important
References: 1270393
This update for shadow fixes the following issues:
- Fix regression about default GID by setting USERGROUPS_ENAB to no Update (bsc#1270393)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3153-1
Released: Tue Jul 21 14:54:24 2026
Summary: Security update for nghttp2
Type: security
Severity: moderate
References: 1269489,CVE-2026-58055
This update for nghttp2 fixes the following issue
- CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning
(bsc#1269489).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3156-1
Released: Tue Jul 21 15:34:44 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1264484,1265421,1267365,1267369,1267494,1267567,1267591,1267618,1267635,1267684,1267722,1267918,1267966,1267993,1268022,1268049,1268237,1268335,1268660,1268989,1269022,1269033,1269036,1269090,1269100,1269159,1269172,1269174,1269184,1269193,1269195,1269310,1269314,1269398,1269493,1269574,1269678,1269681,1269795,1269798,1269821,1269884,1269986,1269993,1270022,1270059,1270257,1271050,1271366,CVE-2026-43109,CVE-2026-46052,CVE-2026-46071,CVE-2026-46076,CVE-2026-46116,CVE-2026-46173,CVE-2026-46229,CVE-2026-46242,CVE-2026-46253,CVE-2026-46266,CVE-2026-46274,CVE-2026-46289,CVE-2026-46319,CVE-2026-46320,CVE-2026-46330,CVE-2026-46331,CVE-2026-52909,CVE-2026-52918,CVE-2026-52923,CVE-2026-52924,CVE-2026-52933,CVE-2026-52943,CVE-2026-52955,CVE-2026-52956,CVE-2026-52958,CVE-2026-52969,CVE-2026-52972,CVE-2026-52993,CVE-2026-53016,CVE-2026-53041,CVE-2026-53052,CVE-2026-53053,CVE-2026-53071,CVE-2026-53072,CVE-2026-53133,CVE-2026-53178,CVE-2026-53182,CVE-2026-53196,CVE-2026-53253,CVE-2026
-53256,CVE-2026-53357,CVE-2026-53359,CVE-2026-53362,CVE-2026-53366
The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues
The following security issues were fixed:
- CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484).
- CVE-2026-46052: ceph: only d_add() negative dentries when they are unhashed (bsc#1267494).
- CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591).
- CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365).
- CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369).
- CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722).
- CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567).
- CVE-2026-46242: eventpoll: Fix integer overflow in ep_loop_check_proc() (bsc#1267618).
- CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635).
- CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684).
- CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966).
- CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022).
- CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993).
- CVE-2026-46330: Revert 'net/smc: Introduce TCP ULP support' (bsc#1268049).
- CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660).
- CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100).
- CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033).
- CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036).
- CVE-2026-52933: io_uring/poll: fix signed comparison in io_poll_get_ownership() (bsc#1268989).
- CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022).
- CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159).
- CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1269172).
- CVE-2026-52958: libceph: Fix potential out-of-bounds access in osdmap_decode() (bsc#1269174).
- CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184).
- CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195).
- CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193).
- CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090).
- CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398).
- CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314).
- CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310).
- CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678).
- CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681).
- CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821).
- CVE-2026-53178: staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction (bsc#1269795).
- CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884).
- CVE-2026-53196: USB: serial: io_ti: fix heap overflow in get_manuf_info() (bsc#1269986).
- CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574).
- CVE-2026-53256: Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (bsc#1269993).
- CVE-2026-53357: Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (bsc#1270257).
- CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059).
- CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493).
- CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271366).
The following non security issues were fixed:
- hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes).
- ipv4: account for fraggap on the paged allocation path (git-fixes).
- ipv6: account for fraggap on the paged allocation path (git-fixes).
- KVM: x86/mmu: Recover TDP MMU NX huge pages using MMU read lock (bsc#1271050).
- KVM: x86/mmu: Rename kvm_tdp_mmu_zap_sp() to better indicate its purpose (bsc#1271050).
- KVM: x86/mmu: Track possible NX huge pages separately for TDP vs. Shadow MMU (bsc#1271050).
- KVM: x86: Fix shadow paging use-after-free due to unexpected role (git-fixes).
- loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303).
- loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303).
- module: fix init_module_from_file() error handling (jsc#PED-16303).
- module: make waiting for a concurrent module loader interruptible (jsc#PED-16303).
- module: Split modules_install compression and in-kernel decompression (jsc#PED-16303).
- module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303).
- module: warn about excessively long module waits (jsc#PED-16303).
- modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303).
- net: mana: Add support for PF device 0x00C1 (bsc#1268237).
- net: mana: Allocate interrupt context for each EQ when creating vPort (git-fixes).
- net: mana: Create separate EQs for each vPort (git-fixes).
- net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git-fixes).
- net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git-fixes).
- net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes).
- net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes).
- net: mana: Optimize irq affinity for low vcpu configs (git-fixes).
- net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes).
- net: mana: Use GIC functions to allocate global EQs (git-fixes).
- RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes).
- RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes).
- scsi: storvsc: Replace symbolic permissions with octal (git-fixes).
- scsi: target: Fix hexadecimal CHAP_I handling (git-fixes).
- x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305).
- x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3163-1
Released: Tue Jul 21 16:50:54 2026
Summary: Security update for pam
Type: security
Severity: moderate
References: 1268290,CVE-2026-54411
This update for pam fixes the following issue
- CVE-2026-54411: timing discrepancy in the pam_userdb module's plaintext-password comparison (bsc#1268290).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3218-1
Released: Thu Jul 23 19:34:12 2026
Summary: Security update for avahi
Type: security
Severity: moderate
References: 1255451,CVE-2025-59529
This update for avahi fixes the following issue:
- CVE-2025-59529: local DoS due to simple protocol server ignoring client limit CLIENTS_MAX (bsc#1255451).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3223-1
Released: Thu Jul 23 20:31:22 2026
Summary: Security update for net-tools
Type: security
Severity: moderate
References: 1254323,CVE-2024-58251
This update for net-tools fixes the following issues:
- CVE-2024-58251: denial of service via terminal escape sequences (bsc#1254323).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3243-1
Released: Fri Jul 24 15:09:32 2026
Summary: Security update for gpg2
Type: security
Severity: low
References: 1269279,CVE-2026-57062
This update for gpg2 fixes the following issue:
- CVE-2026-57062: CMS parsing in gpgsm mishandles the CMS format for AES-GCM (bsc#1269279).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3244-1
Released: Fri Jul 24 15:11:25 2026
Summary: Security update for systemd
Type: security
Severity: moderate
References: 1261400,1261982,1261983,1262305,1267644,1267647,CVE-2026-40226
This update for systemd fixes the following issues
Security issues fixed:
- CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400).
Other updates and bugfixes:
- Fix soft reboot not restarting user services with default.target (bsc#1262305).
- Import commit e46e1952d5 (bsc#1267647 bsc#1262305 bsc#1267644).
- Import commit 429043ca9a (bsc#1261982 bsc#1261983).
- Import commit 58e5d2e21e (bsc#1261982).
- Import commit 4bd91117cc (bsc#1261983).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3261-1
Released: Mon Jul 27 07:51:01 2026
Summary: Recommended update for cifs-utils
Type: recommended
Severity: important
References: 1271183,1271234
This update for cifs-utils fixes the following issues:
- cifs.upcall: fix regression with krb5 + creduid (bsc#1271183, bsc#1271234)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3269-1
Released: Mon Jul 27 13:00:16 2026
Summary: Security update for gzip
Type: security
Severity: important
References: 1269622,CVE-2026-41991
This update for gzip fixes the following issue:
- CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the
user's PATH (bsc#1269622).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3330-1
Released: Tue Jul 28 11:35:51 2026
Summary: Security update for libssh
Type: security
Severity: moderate
References: 1272164,1272165,1272166,1272167,1272168,1272169,1272171,CVE-2026-59843,CVE-2026-59844,CVE-2026-59845,CVE-2026-59846,CVE-2026-59847,CVE-2026-59848,CVE-2026-59850
This update for libssh fixes the following issues:
- CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164).
- CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165).
- CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166).
- CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167).
- CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168).
- CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169).
- CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3341-1
Released: Tue Jul 28 12:09:19 2026
Summary: Security update for glib2
Type: security
Severity: important
References: 1270008,1270009,1270010,1270016,1270018,1270021,CVE-2026-58010,CVE-2026-58011,CVE-2026-58012,CVE-2026-58013,CVE-2026-58014,CVE-2026-58016
This update for glib2 fixes the following issues:
- CVE-2026-58010: error during gvs_tuple_is_normal alignment validation could cause a 1-byte out-of-bounds read
(bsc#1270009).
- CVE-2026-58011: invalid GDateTime in g_date_time_get_ymd could trigger a 2-byte out-of-bounds read (bsc#1270010).
- CVE-2026-58012: raw byte regex matches with UTF-8 functions during case-change replacements could cause an out-of-
bounds read (bsc#1270016).
- CVE-2026-58013: multi-byte custom line terminator in g_io_channel_read_line_backend could trigger an out-of-bounds
read (bsc#1270018).
- CVE-2026-58014: processing empty key file values in g_key_file_get_locale_string_list could cause a 1-byte out-of-
bounds access (bsc#1270021).
- CVE-2026-58016: malformed D-Bus introspection XML could trigger an unsigned integer overflow (bsc#1270008).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3364-1
Released: Tue Jul 28 14:19:32 2026
Summary: Security update for samba
Type: security
Severity: important
References: 1271469,1271672,1271673,1271674,1271675,1271676,1271677,CVE-2026-15779,CVE-2026-58216,CVE-2026-58218,CVE-2026-58221,CVE-2026-58222,CVE-2026-58224,CVE-2026-6949
This update for samba fixes the following issues
- CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672).
- CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation
(bsc#1271469).
- CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674).
- CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication
completes (bsc#1271675).
- CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676).
- CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes
(bsc#1271677).
- CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3397-1
Released: Tue Jul 28 20:31:23 2026
Summary: Security update for python-urllib3
Type: security
Severity: moderate
References: 1268683,CVE-2026-9375
This update for python-urllib3 fixes the following issue
- CVE-2026-9375: decompression bomb bypass in the streaming API when using Brotli support can lead to a denial of
service (bsc#1268683).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3398-1
Released: Wed Jul 29 09:44:21 2026
Summary: Security update for rsyslog
Type: security
Severity: important
References: 1271910
This update for rsyslog fixes the following issue
- input sequence during oversize-frame recovery in imptcp can cause denial of service (bsc#1271910).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3409-1
Released: Wed Jul 29 13:18:15 2026
Summary: Security update for xen
Type: security
Severity: important
References: 1271528,1271530,1271531,1271532,1271533,1271534,1271535,1271536,1271537,1271538,1271539,1271947,CVE-2026-42493,CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425,CVE-2026-62426,CVE-2026-62427,CVE-2026-62428,CVE-2026-62429,CVE-2026-62430,CVE-2026-62431,CVE-2026-62432,CVE-2026-62433,CVE-2026-62434
This update for xen fixes the following issues
- CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528).
- CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530).
- CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531).
- CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532).
- CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534).
- CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535).
- CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536).
- CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537).
- CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538).
- CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539).
- pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3433-1
Released: Thu Jul 30 20:54:35 2026
Summary: Security update for runc
Type: security
Severity: low
References: 1268275,CVE-2025-31133,CVE-2025-52565,CVE-2026-41579
This update for runc fixes the following issues:
Update to 1.3.6.
- CVE-2026-41579: malicious image with a `/dev` symlink can trigger limited host filesystem integrity violations
(bsc#1268275).
Other updates and bugfixes:
- Version 1.3.6:
* When masking directories with `maskPaths`, runc will now re- use a single `tmpfs` instance (which is not writeable)
to reduce the number `tmpfs` superblocks that need to be reaped when containers die (in particular, Kubernetes
applies masks to per-CPU sysfs directories which get expensive quickly).
- Version 1.3.5:
* Recursive atime-related mount flags (rrelatime et al.) are now applied properly.
* PR #4757 caused a regression that resulted in spurious cannot start a container that has stopped errors when
running runc create and has thus been reverted.
* Updated builds to Go 1.25, libseccomp v2.6.0.
* Minor signing keyring updates.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3442-1
Released: Fri Jul 31 21:22:00 2026
Summary: Security update for rsyslog
Type: security
Severity: important
References: 1272414,CVE-2026-61548
This update for rsyslog fixes the following issue:
- CVE-2026-61548: parsing of crafted RFC 5424 messages in `mmpstrucdata` can lead to a stack buffer overflow
(bsc#1272414).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3450-1
Released: Mon Aug 3 13:26:37 2026
Summary: Security update for containerd
Type: security
Severity: moderate
References: 1262266,CVE-2026-33814,CVE-2026-34986,CVE-2026-35469,CVE-2026-39821
This update for containerd fixes the following issues:
- CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service
(bsc#1262266).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3452-1
Released: Mon Aug 3 13:34:50 2026
Summary: Security update for bind
Type: security
Severity: important
References: 1271982,1271983,1271984,1271986,1271987,1271988,1271989,1271990,CVE-2026-10723,CVE-2026-10822,CVE-2026-11331,CVE-2026-11622,CVE-2026-11721,CVE-2026-12617,CVE-2026-13204,CVE-2026-13321
This update for bind fixes the following issues:
- CVE-2026-10723: accepting incorrect child-zone NSEC3 records as valid can allow an attacker to forge authenticated
NXDOMAIN responses for sibling zones (bsc#1271982).
- CVE-2026-10822: storing a DNS key record with an invalid PRIVATEDNS algorithm identifier length can trigger a
consistency check failure (bsc#1271983).
- CVE-2026-11331: handling NAMETOOLONG error conditions incorrectly during RPZ wildcard CNAME processing can allow
bypassing RPZ rules or triggering process exits (bsc#1271984).
- CVE-2026-11622: DNSSEC validating resolver under a random subdomain attack can suffer from runaway memory usage
exceeding max-cache-size and affecting response rate (bsc#1271986).
- CVE-2026-11721: RRSIG with fewer labels than its containing zone when synth-from-dnssec is enabled can lead to
wildcard generation (bsc#1271987).
- CVE-2026-12617: delayed or specific CNAME/DNAME query responses combined with positive A record responses can trigger
an assertion failure (bsc#1271988).
- CVE-2026-13204: validating a domain covered by both NSEC and NSEC3 with an RRSIG for only one type can trigger an
assertion failure (bsc#1271989).
- CVE-2026-13321: NSEC records with a `Next Domain Name` pointing outside the signer's zone can allow cross-zone cache
poisoning and authenticated denial-of-service responses (bsc#1271990).
- Update to release 9.18.50:
* Remove ineffective TCP fallback after repeated UDP timeouts.
* Fall back to TCP on receipt of a UDP response with a mismatched query ID.
* Fix DNS64 owner case after DNAME restart.
* Clear REDIRECT flag when it isn't needed.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3455-1
Released: Mon Aug 3 13:46:45 2026
Summary: Security update for gawk
Type: security
Severity: moderate
References: 1271351,1271352,1271354,CVE-2026-40467,CVE-2026-40468,CVE-2026-40553
This update for gawk fixes the following issues:
- CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351).
- CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352).
- CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3458-1
Released: Mon Aug 3 14:00:20 2026
Summary: Security update for vim
Type: security
Severity: important
References: 1268162,1271193,1271194,1271195,1271684,CVE-2026-59856,CVE-2026-59857,CVE-2026-59858
This update for vim fixes the following issues:
This update for vim fixes the following issues:
Security issues fixed:
- CVE-2026-59856: Arbitrary Code Execution via PHP Omni-Completion (bsc#1271194).
- CVE-2026-59857: Out-of-bounds Write in SAL Soundfolding (bsc#1271195).
- CVE-2026-59858: Arbitrary Code Execution via C Omni-Completion (bsc#1271193).
Non security issue fixed:
- Guard suse.vimrc against re-entry to prevent an infinite sourcing
loop (bsc#1271684).
- allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162).
Changes for vim:
- Updated to version 9.2.0780:
* filetype detect missing from completion (9.2.0726).
* popup images not rendered correctly when unfocused (9.2.0727).
* filetype: supertux info pattern is relative to current dir
(9.2.0728).
* % skips parens on continued quoted lines (9.2.0729).
* GTK4 GUI tabline is not updated (9.2.0730).
* GTK4 GUI scrollbar size not updated when restoring a session
(9.2.0731).
* session: terminal restored using absolute columns/rows (9.2.0732).
* GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733).
* function pointer passed to STRNCMP() instead of a length
(9.2.0734).
* tests: comment test can be improved (9.2.0737).
* completion: 'autocompletedelay' blocks the main loop and drops
autocommands (9.2.0739).
* GTK4: scrollbar wrongly displayed (9.2.0740).
* complete_check() does not return TRUE for mapped input (9.2.0741).
* filetype: SSH keys and related filetypes not recognized (9.2.0742).
* string macros silently accept a size of the wrong type (9.2.0743).
* popup_atcursor() closes immediately on white space (9.2.0744).
* cscope: connection leak when growing the array fails (9.2.0747).
* 'autocompletedelay' interferes with CTRL-G U (9.2.0748).
* 'autocompletedelay' interferes with i_CTRL-K (9.2.0749).
* completion: 'autocompletedelay' deferral leaks state (9.2.0750).
* GTK3 GUI is slow under Wayland (9.2.0751).
* GTK4: drag-and-drop does not support HTML (9.2.0752).
* GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753).
* repeated completion length lookup in search_for_exact_line
(9.2.0754).
* 'autocomplete' behaves inconsistently when recording (9.2.0755).
* session with multiple tabpages sets 'winminheight' to 0 (9.2.0756).
* pum: no opacity when background not set for Popup menu group
(9.2.0758).
* some code for 'autocompletedelay' is no longer needed (9.2.0759).
* compiler warning for using potentially uninitialized var
(9.2.0760).
* runtime(netrw): Unix: unable to open '\' file (9.2.0761).
* duplicated sub-option name check in :set completion (9.2.0762).
* compiler warning about unused function (9.2.0764).
* popup: opacity popup over a terminal is not cleared when moved
(9.2.0765).
* quick_tab entries for empty letters point to the wrong index
(9.2.0766).
* legacy/vim9cmd modifiers do not set script version for options
values (9.2.0767).
* legacy/vim9cmd modifiers are not exclusive (9.2.0768).
* conversion to utf-16be using iconv is inconsistent (9.2.0769).
* dict_add_dict() has inconsistent ownership on failure (9.2.0770).
* dict_add_list() has inconsistent ownership on failure (9.2.0771).
* Vim9: null dereference inside alloc_type() (9.2.0772).
* memory leak in evalfunc.c on alloc failure (9.2.0773).
* memory leak in f_getscriptinfo() on alloc failure (9.2.0774).
* memory leak in highlight_get_info() on alloc failure (9.2.0775).
* memory leak in sign_getlist() on alloc failure (9.2.0776).
* memory leak in add_defer() on alloc failure (9.2.0777).
* memory leak in compile_dict() on alloc failure (9.2.0778).
* memory leak in type_name_func() on alloc failure (9.2.0779).
* memory leak in evalvars.c on alloc failure (9.2.0780).
- Updated to version 9.2.0725:
* GTK: preedit font size is wrong for fractional point sizes (9.2.0532).
* '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533).
* GTK UI does not support fullscreen mode (9.2.0534).
* GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537).
* Cannot keep leading whitespace in %{} statusline expr (9.2.0538).
* filetype: too many Bitbake include files are recognized (9.2.0539).
* Vim9: endclass/endenum/endinterface can give errors (9.2.0541).
* Vim9: wrong error when redeclaring a typed variable (9.2.0543).
* GTK4: window blank after a resize or drag (9.2.0544).
* popup: blending uses hardcoded fallback colors (9.2.0545).
* configure: GTK4 build requires GTK >= 4.10 (9.2.0546).
* '%v' in 'errorformat' is affected by 'tabstop' (9.2.0547).
* GTK4: terminal and pty job output is not processed (9.2.0548).
* Cursor wrong after autoindent strip is skipped (9.2.0549).
* GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550).
* filetype: Tolk files are not recognized (9.2.0551).
* GTK4: F10 does nothing when the menubar is hidden (9.2.0552).
* runtime(netrw): netrw rejects hostnames containing _ (9.2.0553).
* GTK4: memory leak in free_menu() (9.2.0554).
* too many strlen() in ex_substitute() (9.2.0555).
* GTK4: scrollbars not shown and do not respond to clicks (9.2.0556).
* filetype: Kawasaki Robots files are not recognized (9.2.0557).
* filetype: Popcap Reanimation files are not recognized (9.2.0558).
* filetype: Kaitai struct files are not recogonized (9.2.0559).
* filetype: busybox shebang lines are not recognized (9.2.0560).
* [security]: possible code execution with python3complete (9.2.0561).
* filetype: SGF files are not recognized (9.2.0562).
* GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563).
* GTK4: tabline does not respond to mouse clicks (9.2.0564).
* [security]: out-of-bounds read in update_snapshot() (9.2.0565).
* <C-w>f duplicates window if do_ecmd() is aborted (9.2.0566).
* dict function name allocation failure not handled (9.2.0567).
* pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568).
* out-of-bounds access in libvterm CSI 8 t resize (9.2.0569).
* GTK4: mouse wheel scrolling does not work correctly (9.2.0570).
* Vim9: memory leak in compile_nested_function() on failure (9.2.0571).
* lines disappear with wrapping virtual text after a double-width char (9.2.0572).
* Vim9: missing EX_WHOLE on some block keywords (9.2.0573).
* popup_create() not blocked in secure/sandbox (9.2.0576).
* GTK4: window resizing issues (9.2.0577).
* GTK4: :unmenu does not remove entries from the menubar (9.2.0578).
* :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579).
* xxd: binary output is not colored with -R (9.2.0580).
* After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581).
* GTK4: compile error when XFONTSET is defined (9.2.0582).
* completion: indent not ignored for fuzzy line completion (9.2.0583).
* GTK4: missing UI features (9.2.0584).
* line number wrong after undoing a deletion in quickfix buffer (9.2.0585).
* Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586).
* GTK4: left scrollbar overlaps drawarea (9.2.0587).
* GTK4: drawing area loses focus after closing a menubar popover (9.2.0588).
* filetype: xinitrc files are not recognized (9.2.0589).
* GTK4: drawing area loses focus shape on popup menu open (9.2.0590).
* 'scrolljump' ignored when scrolling up (9.2.0591).
* Error when restoring session with terminal window (9.2.0592).
* :wqall ignores term_setkill() on running terminal buffers (9.2.0593).
* Use-after-free with ':wqall' and a running terminal job (9.2.0594).
* MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595).
* cmdline completion popup cannot be scrolled with the mouse (9.2.0596).
* [security]: possible code execution with python complete (9.2.0597).
* popup: title set with popup_setoptions() is not shown (9.2.0599).
* clientserver method needs to be given as argument (9.2.0600).
* matchfuzzypos() returns garbage positions for long candidates (9.2.0601).
* popup: No opacity when background not set for Popup group (9.2.0602).
* possible heap-buffer-overflow when resizing the GUI (9.2.0603).
* GTK4: does not support all clipboard formats (9.2.0606).
* GTK4: inputdialog() does not work as expected (9.2.0607).
* popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608).
* completion info popup cannot be scrolled with the keyboard (9.2.0609).
* cindent: closing brace in a comment affects the next line's indent (9.2.0610).
* MS-Windows: evim.exe not working with VIMDLL (9.2.0611).
* Cannot render images in popup windows (9.2.0612).
* opacity popup leaves stale cells (9.2.0614).
* sixel encoder drops pixels on the right edge of shapes (9.2.0615).
* GTK4: use-after-free on clipboard read timeout (9.2.0616).
* GvimExt: does not support different runtime dirs (9.2.0617).
* use-after-free in popup_getoptions() on dict_add() failure (9.2.0618).
* integer overflow in popup image size validation (9.2.0619).
* runtime(netrw): fix 2match pattern rebuild (9.2.0620).
* 'autoindent' not stripped with virtualedit=onemore (9.2.0621).
* str2blob() does not work with wide UTF-16 encoding (9.2.0622).
* possible integer overflow in spellfile tree bounds check (9.2.0623).
* C-N/C-P cannot be mapped in complete() completion (9.2.0624).
* GTK4: Link error when Wayland is disabled (9.2.0625).
* Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626).
* :vim9cmd source handles all scripts as Vim9 script (9.2.0627).
* popup image: wrong overlap layering, kitty laggy (9.2.0628).
* 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629).
* popup images: kitty images output in GUI mode (9.2.0630).
* DECRQM and SGR Mouse not supported in foot terminal (9.2.0631).
* GTK4: no support for hardware-accelerated rendering (9.2.0632).
* MS-Windows: No support for kitty graphics support in terminal (9.2.0633).
* GTK4: no minimum resize limit (9.2.0634).
* checking the syntax contains/cluster list is slow (9.2.0635).
* popup image: stale pixels under RGBA animation frames (9.2.0636).
* sixel: anti-aliased RGBA images render with visible outline (9.2.0637).
* cannot return matches containing spaces from a custom completion (9.2.0638).
* gq with 'formatprg' fails on an empty buffer (9.2.0639).
* the '%' command jumps to parens and braces inside comments (9.2.0640).
* GTK4: crash in gui_mch_menu_hidden() (9.2.0641).
* statusline: buffer overflow with item groups (9.2.0642).
* Missing Image ifdefs (9.2.0643).
* popup image: duplicate sync-output code (9.2.0644).
* Composing chars no longer accepted in end-id abbr (9.2.0645).
* GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646).
* matchfuzzypos() false exact match for long equal-length candidates (9.2.0647).
* MS-Windows: Compile warnings (9.2.0648).
* filetype: tf files sometimes incorrectly recognized (9.2.0649).
* Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650).
* completion: 'smartcase' doesn't work with 'longest' (9.2.0651).
* popup: stale kitty image after clipwindow scrolls out of view (9.2.0652).
* [security]: out-of-bounds write in tree_count_words() (9.2.0653).
* GTK4: using uninitialised colors in gui_mch_init() (9.2.0654).
* GTK4: missing NULL checks in vim_form_measure() (9.2.0655).
* completion: using wrong tolower() in smartcase filtering (9.2.0656).
* GTK4: missing menu when right-clicking in tabline (9.2.0657).
* xxd: signed integer overflow in huntype() (9.2.0658).
* GTK4: no balloon support in GUI (9.2.0659).
* Dragging the scrollbar does not trigger WinScrolled (9.2.0660).
* unintended wipe of Vim's temp dir, causes errors (9.2.0661).
* [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662).
* [security]: runtime(netrw): code injection in local file deletion (9.2.0663).
* GTK4: GTK critical error on exit printed (9.2.0665).
* Terminal-Normal mode does not color empty lines with a background color (9.2.0666).
* patch 9.2.0590 was wrong (9.2.0667).
* GTK4: minimum horizontal size is too small (9.2.0668).
* GTK4: toolbar can be improved (9.2.0669).
* [security]: Out-of-bounds read with text properties (9.2.0670).
* [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671).
* corrupted text property causes internal error (9.2.0672).
* configure: clears dynamic ruby linker flags (9.2.0674).
* MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676).
* Cannot clear the alternate file register # (9.2.0677).
* [security]: potential powershell code execution in zip.vim (9.2.0678).
* [security]: Out-of-bounds read with text property virtual text (9.2.0679).
* keytrans() doesn't replace '|' and '\' (9.2.0680).
* configure: -lruby added even for a dynamic ruby build (9.2.0681).
* Wrong dot-repeat when calling complete() while filtering completion (9.2.0682).
* filetype completion mishandles finished sub options (9.2.0683).
* :reg # does not display the value of the '#' register (9.2.0684).
* clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685).
* style: strcmp usage is inconsistent (9.2.0686).
* popup_image_composites_frames() has improper if block scope (9.2.0687).
* Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688).
* the '%' command is slow on a long line with many slashes (9.2.0689).
* Solaris: swap file names are too long (9.2.0690).
* Solaris: Test_terminal_composing_unicode() fails (9.2.0691).
* GTK2: build failure, popup images not drawn correctly (9.2.0692).
* Solaris: some tests faiures due to Solaris peculiarities (9.2.0694).
* Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695).
* GTK4: A few issues with toolbar support (9.2.0696).
* possible overflow when parsing CSI keys (9.2.0697).
* [security]: Out-of-bounds write with soundfold() (9.2.0698).
* [security]: possible code execution with python complete (9.2.0699).
* configure: -lrt requirement for timer_create not detected (9.2.0700).
* :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702).
* session file does not store relative Vim9 autoload imports (9.2.0703).
* GTK4: not handling mouse events (9.2.0704).
* :delete # silently fails to update '# and clobbers '0 (9.2.0705).
* completion: popup misplaced when text before it is concealed (9.2.0707).
* Leaks in do_autocmd in error case (9.2.0708).
* GTK4: a few minor issues (9.2.0709).
* GTK4 GUI resize handling can be improved (9.2.0710).
* leak in ins_compl_infercase_gettext() in error case (9.2.0711).
* GTK4: dialogs not handling mnemonics correctly (9.2.0712).
* completion: ruler not updated correctly when the popup menu is visible (9.2.0713).
* Coverity warns for NULL deref (9.2.0714).
* Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715).
* filetype: not all supertux files are recognized (9.2.0716).
* :syn sync without an argument also lists syntax cluster (9.2.0718).
* GTK4: default menu is lacking (9.2.0719).
* GTK4: no support for browsefilter (9.2.0720).
* serverlist() returns strings separated by \n (9.2.0721).
* GTK4: find/replace dialog can be improved (9.2.0722).
* term_start() does not support 'noclose' (9.2.0723).
* use-after-free when freeing exit_cb job on exit (9.2.0724).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3493-1
Released: Tue Aug 4 14:11:00 2026
Summary: Security update for libpng16
Type: security
Severity: important
References:
This update for libpng16 fixes the following issues:
Changes for libpng16:
- version update to 1.6.58 (jsc#PED-16190).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3515-1
Released: Thu Aug 6 13:08:56 2026
Summary: Security update for openssl-1_1
Type: security
Severity: important
References: 1271712
This update for openssl-1_1 fixes the following issue
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3516-1
Released: Thu Aug 6 13:09:13 2026
Summary: Security update for openssl-3
Type: security
Severity: important
References: 1271712
This update for openssl-3 fixes the following issue
- HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker-controlled memory allocations
(bsc#1271712).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3558-1
Released: Mon Aug 10 20:01:21 2026
Summary: Security update for perl
Type: security
Severity: important
References: 1266304,1268349,1271372,CVE-2026-12087,CVE-2026-57432,CVE-2026-8376
This update for perl fixes the following issues:
- CVE-2026-8376: heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds
(bsc#1266304).
- CVE-2026-12087: `Socket`'s `pack_ip_mreq_source()` can copy adjacent heap memory into the returned packed structure
(bsc#1268349).
- CVE-2026-57432: an integer overflow in `S_measure_struct` leads to an out-of-bounds heap read in `pack` and `unpack`
(bsc#1271372).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3560-1
Released: Mon Aug 10 20:09:08 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1264962,1265268,1267581,1267821,1268375,1268977,1269066,1269788,1269959,1271192,CVE-2026-0864,CVE-2026-11940,CVE-2026-11972,CVE-2026-15308,CVE-2026-3276,CVE-2026-4360,CVE-2026-7210,CVE-2026-7774,CVE-2026-8328
This update for python311 fixes the following issues:
Security issues fixed:
- CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the
`configparser` module is used (bsc#1269066).
- CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted
Unicode input (bsc#1267581).
- CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting
hardlinks (bsc#1269959).
- CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding
protection (bsc#1264962).
- CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory
(bsc#1267821).
- CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server-supplied PASV host address (bsc#1265268).
- CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and
enables arbitrary file reads and writes (bsc#1268977).
- CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS
(bsc#1269788).
- CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations
(bsc#1271192).
Non security issue fixed:
- [kernel 7.1] udplite was removed -> python fails in tests (bsc#1268375).
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3566-1
Released: Tue Aug 11 07:33:57 2026
Summary: Recommended update for grub2
Type: recommended
Severity: important
References: 1271980
This update for grub2 fixes the following issues:
- Fix crash in booting kernel on some AMD systems (bsc#1271980)
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3582-1
Released: Tue Aug 11 16:35:48 2026
Summary: Recommended update for timezone
Type: recommended
Severity: moderate
References:
This update for timezone fixes the following issues:
- Update to 2026c:
* Alberta moved to permanent -06 on 2026-06-18.
* Morocco moves to permanent +00 on 2026-09-20.
* More integer overflow bugs have been fixed in zic.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3592-1
Released: Wed Aug 12 11:15:00 2026
Summary: Security update for gzip
Type: security
Severity: moderate
References: 1269623,1272554,CVE-2026-41992
This update for gzip fixes the following issues:
- CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state
between different decompression formats within a single execution (bsc#1269623).
- Crafted LZW file followed by a crafted LZH file can cause an out-of-bounds memory buffer access (bsc#1272554).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3600-1
Released: Wed Aug 12 13:59:10 2026
Summary: Security update for rpm
Type: security
Severity: important
References: 1240054,1269584,CVE-2026-44605
This update for rpm fixes the following issues:
Security issues fixed:
- CVE-2026-44605: heap buffer overflow in NDB database backend due to unchecked 32-bit arithmetic when parsing the slot
table (bsc#1269584).
Other updates and bugfixes:
- Fix `libelf` handle not being closed, resulting in build errors when using a NFS buildroot (bsc#1240054).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3602-1
Released: Wed Aug 12 20:35:45 2026
Summary: Security update for the Linux Kernel
Type: security
Severity: important
References: 1185845,1243603,1253262,1258718,1260347,1262573,1262745,1262771,1263010,1263068,1263718,1263788,1264013,1264053,1264076,1264089,1264090,1264558,1264779,1264795,1265308,1266238,1266758,1266850,1266890,1266913,1267375,1267384,1267435,1267584,1267596,1267656,1267682,1267715,1267995,1268029,1268307,1269181,1269188,1269289,1269383,1269512,1269513,1269577,1269633,1269773,1269808,1269981,1269988,1269997,1270000,1270230,1271349,1271368,1271526,1271825,1271866,1271899,1271904,1271908,1271912,1271964,1272176,1272180,1272183,1272207,1272242,1272263,1272268,1272282,1272466,1272468,1272573,1272607,1272665,1272678,1272693,1272694,1272836,1272855,1272865,1272904,1272907,1272918,1273004,1273035,1273231,1274072,CVE-2023-2058,CVE-2025-54518,CVE-2026-31431,CVE-2026-31482,CVE-2026-31483,CVE-2026-31542,CVE-2026-31598,CVE-2026-31628,CVE-2026-31759,CVE-2026-43033,CVE-2026-43046,CVE-2026-43056,CVE-2026-43276,CVE-2026-43440,CVE-2026-43475,CVE-2026-45904,CVE-2026-46056,CVE-2026-46080,CVE-2026-460
84,CVE-2026-46109,CVE-2026-46117,CVE-2026-46126,CVE-2026-46144,CVE-2026-46145,CVE-2026-46174,CVE-2026-46193,CVE-2026-46243,CVE-2026-46323,CVE-2026-46324,CVE-2026-46333,CVE-2026-52967,CVE-2026-52986,CVE-2026-53050,CVE-2026-53129,CVE-2026-53131,CVE-2026-53177,CVE-2026-53224,CVE-2026-53246,CVE-2026-53250,CVE-2026-53262,CVE-2026-53267,CVE-2026-53297,CVE-2026-53324,CVE-2026-53354,CVE-2026-53375,CVE-2026-53388,CVE-2026-53391,CVE-2026-53402,CVE-2026-63794,CVE-2026-63802,CVE-2026-63806,CVE-2026-63807,CVE-2026-63824,CVE-2026-63826,CVE-2026-63829,CVE-2026-63884,CVE-2026-63893,CVE-2026-63912,CVE-2026-63917,CVE-2026-63919,CVE-2026-63921,CVE-2026-63922,CVE-2026-63924,CVE-2026-63946,CVE-2026-63952,CVE-2026-63968,CVE-2026-63971,CVE-2026-63975,CVE-2026-63984,CVE-2026-63994,CVE-2026-64106,CVE-2026-64189,CVE-2026-64530,CVE-2026-64560,CVE-2026-64561,CVE-2026-64564,CVE-2026-64600
The SUSE Linux Enterprise 15 SP6 kernel was updated to fix various security issues:
The following security issues were fixed:
- CVE-2026-46056: Bluetooth: hci_event: fix potential UAF in SSP passkey handlers (bsc#1267435).
- CVE-2026-46193: xfrm: ah: account for ESN high bits in async callbacks (bsc#1267656).
- CVE-2026-46324: netfilter: nf_tables: Introduce functions freeing nft_hook objects (bsc#1267995).
- CVE-2026-52967: smb/client: fix possible infinite loop and oob read in symlink_data() (bsc#1269181).
- CVE-2026-52986: netfilter: nf_conntrack_sip: don't use simple_strtoul (bsc#1269289).
- CVE-2026-53050: quota: Fix race of dquot_scan_active() with quota deactivation (bsc#1269188).
- CVE-2026-53129: fs/mbcache: cancel shrink work before destroying the cache (bsc#1269633).
- CVE-2026-53131: netfilter: require Ethernet MAC header before using eth_hdr() (bsc#1269773).
- CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1269997).
- CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1269988).
- CVE-2026-53250: xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() (bsc#1269808).
- CVE-2026-53262: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() (bsc#1270000).
- CVE-2026-53267: netfilter: nft_ct: bail out on template ct in get eval (bsc#1269577).
- CVE-2026-53354: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1270230).
- CVE-2026-53375: drm/amdgpu/vce: Prevent partial address patches (bsc#1271899).
- CVE-2026-53388: fuse: re-lock request before replacing page cache folio (bsc#1271825).
- CVE-2026-53391: NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr (bsc#1271904).
- CVE-2026-53402: fbdev: fbcon: fix out-of-bounds read in err_out of (bsc#1271908).
- CVE-2026-63794: KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (bsc#1271964).
- CVE-2026-63802: blk-cgroup: fix UAF in __blkcg_rstat_flush() (bsc#1272282).
- CVE-2026-63806: KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unaligned() (bsc#1272268).
- CVE-2026-63807: KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (bsc#1272263).
- CVE-2026-63824: KEYS: fix overflow in keyctl_pkey_params_get_2() (bsc#1272180).
- CVE-2026-63826: fbdev: fix use-after-free in store_modes() (bsc#1272183).
- CVE-2026-63829: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink (bsc#1272176).
- CVE-2026-63884: drm/i915: Fix potential UAF in TTM object purge (bsc#1272573).
- CVE-2026-63893: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (bsc#1272607).
- CVE-2026-63912: xfrm: esp: restore combined single-frag length gate (bsc#1272836).
- CVE-2026-63917: ip6: vti: Use ip6_tnl.net in vti6_changelink() (bsc#1272904).
- CVE-2026-63919: xfrm: input: hold netns during deferred transport reinjection (bsc#1272907).
- CVE-2026-63921: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate() (bsc#1272918).
- CVE-2026-63922,CVE-2026-63924: ipv6: exthdrs: refresh nh after handling HAO option (bsc#1272855).
- CVE-2026-63946: Bluetooth: ISO: fix UAF in iso_recv_frame (bsc#1272665).
- CVE-2026-63952: memfd: deny writeable mappings when implying SEAL_WRITE (bsc#1272468).
- CVE-2026-63968: ipv6: fix possible infinite loop in fib6_select_path() (bsc#1272466).
- CVE-2026-63971: sctp: fix race between sctp_wait_for_connect and peeloff (bsc#1272678).
- CVE-2026-63975: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (bsc#1272694).
- CVE-2026-63984: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() (bsc#1272865).
- CVE-2026-63994: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp() (bsc#1273035).
- CVE-2026-64106: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (bsc#1272242).
- CVE-2026-64189: netfilter: ipset: fix race between dump and ip_set_list resize (bsc#1272207).
- CVE-2026-64560: posix-cpu-timers: Prevent UAF caused by non-leader exec() race (bsc#1273004).
- CVE-2026-64561: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available (bsc#1273231).
- CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (bsc#1274072).
- CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (bsc#1271526).
The following non security issues were fixed:
- Drivers: hv: vmbus: Set DMA coherent mask for VMBus devices (git-fixes).
- hrtimers: Introduce hrtimer_setup() to replace hrtimer_init() (bsc#1271912).
- ice: don't check has_ready_bitmap in E810 functions (bsc#1269981).
- ice: factor out ice_ptp_rebuild_owner() (bsc#1269981).
- ice: fix PTP Call Trace during PTP release (bsc#1269981).
- ice: Fix PTP NULL pointer dereference during VSI rebuild (bsc#1269981).
- ice: introduce PTP state machine (bsc#1269981).
- ice: pass reset type to PTP reset functions (bsc#1269981).
- ice: rename ice_ptp_tx_cfg_intr (bsc#1269981).
- ice: rename verify_cached to has_ready_bitmap (bsc#1269981).
- ice: stop destroying and reinitalizing Tx tracker during reset (bsc#1269981).
- KVM: SVM: Mark VMCB_NPT as dirty on nested VMRUN (git-fixes).
- KVM: SVM: Mark VMCB_PERM_MAP as dirty on nested VMRUN (git-fixes).
- KVM: x86/mmu: Fix use-after-free on vendor module reload (git-fixes).
- KVM: x86/mmu: Preserve nested TDP shadow page tables if they are used as roots (git-fixes).
- KVM: x86/xen: Fix cleanup logic in emulation of Xen schedop poll hypercalls (git-fixes).
- KVM: x86: Fix SRCU list traversal in kvm_fire_mask_notifiers() (git-fixes).
- KVM: x86: Fix VM hard lockup after prolonged inactivity with periodic HV timer (git-fixes).
- KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git-fixes).
- KVM: x86: hyper-v: Validate all GVAs during PV TLB flush (git-fixes).
- mkspec-dtb: Skip missing DTBs.
- net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_handle (bsc#1271866).
- net: mana: Add Interrupt Moderation support (bsc#1271368).
- net: mana: Return error code from mana_create_rxq() (git-fixes).
- net: mana: Validate the packet length reported by the NIC (git-fixes).
- pkspec-dtb: Fix dtb-al rename.
- posix-cpu-timers: Cleanup the firing logic (bsc#1271912).
- posix-cpu-timers: Correctly update timer status in posix_cpu_timer_del() (bsc#1271912).
- posix-cpu-timers: Do not arm SIGEV_NONE timers (bsc#1271912).
- posix-cpu-timers: Handle interval timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_get() (bsc#1271912).
- posix-cpu-timers: Handle SIGEV_NONE timers correctly in timer_set() (bsc#1271912).
- posix-cpu-timers: Make k_itimer::it_active consistent (bsc#1271912).
- posix-cpu-timers: Remove incorrect comment in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Replace old expiry retrieval in posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Simplify posix_cpu_timer_set() (bsc#1271912).
- posix-cpu-timers: Split up posix_cpu_timer_get() (bsc#1271912).
- posix-cpu-timers: Use @now instead of @val for clarity (bsc#1271912).
- posix-timers: Add proper state tracking (bsc#1271912).
- posix-timers: Avoid direct access to hrtimer clockbase (bsc#1271912).
- posix-timers: Clarify posix_timer_fn() comments (bsc#1271912).
- posix-timers: Clear overrun in common_timer_set() (bsc#1271912).
- posix-timers: Consolidate signal queueing (bsc#1271912).
- posix-timers: Consolidate timer setup (bsc#1271912).
- posix-timers: Cure si_sys_private race (bsc#1271912).
- posix-timers: Document common_clock_get() correctly (bsc#1271912).
- posix-timers: Expand timer_arm() callbacks with a boolean return value (bsc#1271912).
- posix-timers: Polish coding style in a few places (bsc#1271912).
- posix-timers: Retrieve interval in common timer_settime() code (bsc#1271912).
- RDMA/mana_ib: initialize err for empty send WR lists (git-fixes).
- sctp: validate embedded address parameter length (git-fixes).
- time: Switch to hrtimer_setup() (bsc#1271912).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3605-1
Released: Thu Aug 13 08:35:24 2026
Summary: Security update for openssh
Type: security
Severity: important
References: 1271044,1271046,1271048,1271049,1271052,1271053,1271054,1271055,CVE-2026-59995,CVE-2026-59996,CVE-2026-59997,CVE-2026-59998,CVE-2026-59999,CVE-2026-60000,CVE-2026-60001,CVE-2026-60002
This update for openssh fixes the following issues:
- Backported support for the mlkemx25519 key exchange from upstream (jsc#PED-16473).
- CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with
an attacker-controlled server (bsc#1271044).
- CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two
remote destinations (bsc#1271046).
- CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048).
- CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory
is not documented (bsc#1271049).
- CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052).
- CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053).
- CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054).
- CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange
(bsc#1271055).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3612-1
Released: Thu Aug 13 19:58:56 2026
Summary: Security update for dracut
Type: security
Severity: important
References: 1274432,CVE-2026-15816
This update for dracut fixes the following issue:
Update to version 059+suse.567.gf5cfeb7f7.
Securitys issue fixed:
- CVE-2026-15816: root code execution via unescaped error message written to sourced emergency-hook script in `die()`
(bsc#1274432).
Other updates and bugfixes:
- Fix(base): sanitize message written by `die()` to the emergency hook.
- Feat(base): add escape function implementing `printf %q`.
-----------------------------------------------------------------
Advisory ID: SUSE-RU-2026:3646-1
Released: Wed Aug 19 07:40:47 2026
Summary: Recommended update for rsyslog
Type: recommended
Severity: important
References: 1264721
This update for rsyslog fixes the following issues:
- Added a devel subpackage, with requires (bsc#1264721)
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3648-1
Released: Wed Aug 19 11:54:08 2026
Summary: Security update for python311
Type: security
Severity: important
References: 1263083,CVE-2026-3276,CVE-2026-6019
This update for python311 fixes the following issues:
- Regression in `http.cookies` (bsc#1263083).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3670-1
Released: Fri Aug 21 09:15:07 2026
Summary: Security update for containerd
Type: security
Severity: important
References:
This update for containerd rebuilds it against the current go security release.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3680-1
Released: Fri Aug 21 16:21:23 2026
Summary: Security update for vim
Type: security
Severity: important
References: 1275011,1275012,1275013,1275014,1275015,1275016,1275017,1275018,CVE-2026-73070,CVE-2026-73071,CVE-2026-73072,CVE-2026-73074,CVE-2026-73075,CVE-2026-73076,CVE-2026-73077,CVE-2026-73078
This update for vim fixes the following issues:
- CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018).
- CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017).
- CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution
(bsc#1275016).
- CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution
(bsc#1275015).
- CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014).
- CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013).
- CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012).
- CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011).
Changes for vim:
- Updated to version 9.2.0957.
* tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781).
* tests: missing cleanup in test_mksession.vim (9.2.0782).
* tests: personal spell files leak into later tests (9.2.0783).
* crash when borrowing statusline highlight in silent Ex mode (9.2.0784).
* WinResized not triggered when the whole Vim is resized (9.2.0785).
* filetype: containerfile is not recognized (9.2.0786).
* regexp: code 0x1ecb duplicated for equivalence class (9.2.0787).
* filetype: hip files are not recognized (9.2.0788).
* 'statuslineopt' status line too high after a window is minimized (9.2.0789).
* 'completeslash' breaks :find completion with 'findfunc' (9.2.0790).
* wincol() counts from right side for 'rightleft' (9.2.0791).
* runtime(netrw): explore without optional dir broken (9.2.0792).
* if session restored a tiny window, restore fails (9.2.0793).
* extend() and extendnew() don't handle NULL expr2 properly (9.2.0794).
* popup menu shadow is not cleared when the menu shrinks (9.2.0795).
* Visual block reselection wrong with 'virtualedit' (9.2.0796).
* memory leak in get_qfline_items() on alloc failure (9.2.0797).
* memory leak in compile_expr6() on alloc failure (9.2.0798).
* memory leak in compile_def_function_body() on alloc failure (9.2.0799).
* memory leak in call_func() on alloc failure (9.2.0800).
* memory leak in f_getreginfo() on alloc failure (9.2.0801).
* memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802).
* memory leak on alloc failure with taglist/gettagstack() (9.2.0803).
* wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804).
* screenpos() 'curscol' is wrong with 'rightleft' (9.2.0805).
* 'showcmd' may show internal command keys (9.2.0806).
* MS-Windows: ellipsis character is garbled (9.2.0807).
* getregionpos: double-free on alloc failure (9.2.0808).
* getframelayout() uses wrong function to free lists (9.2.0809).
* add_llist_tags() uses wrong function to free dict (9.2.0810).
* mksession writes terminal command unquoted (9.2.0811).
* :argdelete with pattern leads to wrong argidx() (9.2.0812).
* dict_add_func() may corrupt funcref count on failure (9.2.0813).
* Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814).
* deeply nested regexp patterns may cause stack overflow (9.2.0815).
* GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816).
* crash when building a stacktrace during an autocommand (9.2.0817).
* tests: client-server test fails without X11 server (9.2.0818).
* MS-Windows: sixel image shown as raw text in the console (9.2.0819).
* GUI: hidden popup image is displayed and not erased (9.2.0820).
* filetype: msmtp system-wide rc file not detected (9.2.0821).
* GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822).
* tests: Test_clientserver_servlist_list may fail (9.2.0823).
* Makefile: make tags depends on configure (9.2.0824).
* regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825).
* highlighting for broken terminals can be improved (9.2.0826).
* :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827).
* GTK4: hardware rendering can be improved (9.2.0828).
* sessions do not preserve script version for expression options (9.2.0829).
* the completion menu is not used on terminals without colors (9.2.0830).
* diff highlighting hard to read with syntax enabled (9.2.0831).
* socketserver: remote commands can be processed in reverse order (9.2.0832).
* GTK4: menu mnemonics do not work properly (9.2.0833).
* cleared last search pattern is restored from viminfo (9.2.0834).
* features in version.c are not sorted (9.2.0835).
* filetype: .git-blame-ignore-revs file is not recognized (9.2.0836).
* using wrong colors in hl_blend_attr() (9.2.0837).
* searchcount() returns wrong cached maxcount (9.2.0838).
* [security]: arbitrary code execution via keyword lookup (9.2.0839).
* [security]: code injection in netrw via bookmarks (9.2.0840).
* [security]: heap overflow when adding > 65535 text properties (9.2.0841).
* [security]: stack buffer overflow in socket server (9.2.0842).
* [security]: popup: opacity mask indexed out of bounds (9.2.0843).
* [security]: use-after-free on json decode error (9.2.0844).
* [security]: arbitrary Ex command execution during C omni-completion (9.2.0845).
* [security]: heap buffer overflow in set_sofo() (9.2.0846).
* [security]: vimball: code execution via .VimballRecord file (9.2.0847).
* tagfunc 'cmd' with a generic Ex command corrupts the tag entry (9.2.0848).
* filetype: osquery config files are not recognized (9.2.0849).
* MS-Windows: commands from a client can be lost (9.2.0850).
* focus autocommands triggered inconsistently (9.2.0851).
* GTK: ligatures not correctly displayed (9.2.0852).
* popup: popup images do not support scaling (9.2.0853).
* memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854).
* 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855).
* GTK4: undercurl rendering is inefficient (9.2.0856).
* popup: opacity popup over a terminal is not cleared when closed (9.2.0857).
* MS-Windows GUI: white flash when VimEnter is slow (9.2.0858).
* GTK2: link error (9.2.0859).
* filetype: xilinx design constraint files are not recognized (9.2.0860).
* GTK4: bleed region updates in jumps (9.2.0861).
* missing test change from v9.2.0857 (9.2.0862).
* MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863).
* using some dead code in Wayland feature (9.2.0864).
* GTK4: non-hardware accelerated UI is too slow (9.2.0865).
* MS-Windows: ':language messages' only works once (9.2.0866).
* MS-Windows: messages are not in the display language (9.2.0867).
* GTK: window Manager hint prevents giving focus to dialog (9.2.0868).
* buf_copy_options() can lose the P_INSECURE flag (9.2.0869).
* filetype: marko files are not recognized (9.2.0870).
* screen line is lost when splitting a 'winfixheight' window (9.2.0871).
* popup with opacity does not use the font of the highlight group (9.2.0872).
* :redrawstatus does not update the ruler of the last window (9.2.0873).
* fold size is compared against 'foldminlines' of the wrong window (9.2.0874).
* GTK4: GUI does not support command-line arguments (9.2.0875).
* GTK4: compile error with disabled netbeans feat (9.2.0876).
* Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877).
* Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878).
* popup: 'maxwidth' is not respected when 'wrap' is off (9.2.0879).
* scroll: window scrolls when using the autocommand window (9.2.0880).
* 'smoothscroll' position is lost when the window height changes (9.2.0881).
* :bwipe crashes if WinLeave wipes all other buffers (9.2.0882).
* scroll: 'smoothscroll' position is lost when using '|' (9.2.0883).
* scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884).
* scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885).
* :set completion works for an invalid sub-option name (9.2.0886).
* scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887).
* mapping: modifier is not recognized after a partial mapping (9.2.0888).
* VMS: spurious 'INVALID DECC FEATURE VALUE' message at every startup (9.2.0889).
* test: test for patch v9.2.0888 can be clarified (9.2.0890).
* MS-Windows: filename-modifier ':8:t' causes underflow (9.2.0891).
* highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892).
* MS-Windows: '*.vim' also matches files with a longer extension (9.2.0893).
* filetype: ed script files not recognised (9.2.0894).
* test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895).
* scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896).
* GTK3 X11 redraws are not coalesced (9.2.0897).
* printing support is lacking (9.2.0898).
* command output temporary files may collide (9.2.0899).
* FocusGained still triggered when closing dialog (9.2.0900).
* textprop: wrong cursor line with truncated virtual text (9.2.0901).
* Vim9: iterating over a tuple leaks memory (9.2.0902).
* Vim9: cannot use an exported function of an autoload import (9.2.0903).
* 'zb' scrolls incorrectly with cursor just above fold (9.2.0904).
* MS-Windows: ghost cursor with ligatures (9.2.0905).
* slow transstr() with long strings (9.2.0906).
* popup: virtual text is not redrawn when a text property changes (9.2.0907).
* cannot use a {} block in a nested :autocmd (9.2.0908).
* insert completion is slow to collect many matches (9.2.0909).
* runtime(vim): update syntax, contain Ex commands (9.2.0910).
* makefiles do not build hardcopy_postscript.c (9.2.0911).
* hardcopy: prototypes are hand-written instead of generated (9.2.0912).
* statusline: cell below the vertical separator keeps the old highlight (9.2.0913).
* diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914).
* tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915).
* configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916).
* :quitall not allowed in the command-line window (9.2.0917).
* screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918).
* screen: the wrong array is copied into ScreenCols on a resize (9.2.0919).
* filetype: json-ld files are not recognized (9.2.0920).
* test: terminal tests fail on FreeBSD (9.2.0921).
* Wayland: modeless selection not redrawn (9.2.0922).
* tabpage: closing a tab page loses the alternate tab page (9.2.0923).
* tests: Test_termwinscroll() fails on FreeBSD (9.2.0924).
* crash when getcompletiontype() gets a NULL string (9.2.0925).
* filetype: business Central files are not recognized (9.2.0926).
* curswant not set on 8g8 (9.2.0927).
* MinGW: tests hang when Vim is built with coverage enabled (9.2.0928).
* incorrect completion for 'pumopt' and 'pumborder' (9.2.0929).
* floating point exception when displaying pum (9.2.0930).
* the GTK4 GUI is still experimental and untested by CI (9.2.0931).
* NFA engine fallback can double free the compiled program (9.2.0932).
* u_read_undo() leaks the file name when the undo file owner differs (9.2.0933).
* filetype: hlsl files are not recognized (9.2.0934).
* reading an undo file is slow with many undo headers (9.2.0935).
* stringifying a list or dict can free the item being iterated (9.2.0936).
* sort() with a numeric option converts each item on every comparison (9.2.0937).
* cursorbind: cursor in the other window is not updated after undo (9.2.0938).
* mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939).
* GTK4: columns are lost when a scrollbar appears (9.2.0940).
* tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941).
* test: test_mksession_winpos() fails on GTK4 UI (9.2.0942).
* test: test_hardcopy fails on GTK4 UI (9.2.0943).
* test: tests fail when checking for GTK4 feature (9.2.0944).
* sort() with a numeric option can be improved (9.2.0945).
* GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946).
* GTK4: screen is cleared when moving the mouse after startup (9.2.0947).
* GTK4: mouse move starts Visual selection after a dialog (9.2.0948).
* GDK_KEY_VoidSymbol might be undefined (9.2.0949).
* transstr() can be improved (after 9.2.0906) (9.2.0950).
* GTK3: cursor does no longer blink (9.2.0951).
* locking a container while stringifying can be improved (9.2.0952).
* insert completion code can be improved (9.2.0953).
* u_read_undo() can be improved (after 9.2.0935) (9.2.0954).
* tests: terminal tests are flaky (9.2.0955).
* GTK4: crash when the window is resized while redrawing (9.2.0956).
* filetype: ArgoCD config file is not recognized (9.2.0957).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3685-1
Released: Fri Aug 21 20:23:55 2026
Summary: Security update for util-linux
Type: security
Severity: important
References: 1261606,1268886,1269583,CVE-2026-13595,CVE-2026-27456,CVE-2026-53612,CVE-2026-53613,CVE-2026-53614
This update for util-linux fixes the following issues:
- CVE-2026-13595: heap use-after-free read in `libblkid` nested partition probing (bsc#1269583).
- CVE-2026-27456: TOCTOU race condition in the mount program when setting up loop devices (bsc#1261606).
- Several security issues in releases prior to v2.42.2 and v2.41.5 (bsc#1268886).
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3783-1
Released: Tue Aug 25 10:10:55 2026
Summary: Security update for containerd
Type: security
Severity: important
References:
This update for containerd rebuilds it against the current go security release.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3787-1
Released: Tue Aug 25 10:15:16 2026
Summary: Security update for runc
Type: security
Severity: important
References:
This update for runc rebuilds it against the current go security release.
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3840-1
Released: Thu Aug 27 14:21:12 2026
Summary: Security update for wicked
Type: security
Severity: important
References: 1265221,1274627,CVE-2026-44932,CVE-2026-71401,CVE-2026-71402
This update for wicked fixes the following issues:
Update to version 0.6.79.
- CVE-2026-44932: indirect remote shell command injection due to insufficient sanitization of DHCP options written to
`/run/wicked/leaseinfo.*` files (bsc#1265221).
- CVE-2026-71401: out-of-bounds read due to IP length underflow in checksum handling of DHCPv4 capture parsing
(bsc#1274627).
- CVE-2026-71402: out-of-bounds read due to DHCP option reader being extended beyond provided allocation in DHCPv4
capture parsing (bsc#1274627).
Changes for wicked:
- Version 0.6.79:
- Fix to escape single-quotes in leaseinfo dump output used by the `wicked test dhcp4` and `wicked test dhcp6` and
written to the `/run/wicked/leaseinfo.*` files, e.g. to pass them to `netconfig`.
- Fix `posix-tz-dbname` and `tz-string` option processing checks to permit only valid characters according to
RFC4833.
- Discard string values containing single-quotes in other options.
- Trigger to regenerate `initrd` that may contain wicked binaries on updates from wicked versions <= 0.6.78.
- Version 0.6.78:
- `man`: small fixes in wireless manpage (gh#opensuse/wicked#1053)
- `rtnetlink`: fix `RTM_NEWLINK` name resolution in debug (gh#opensuse/wicked#1052)
- Add support for IPVLAN/IPVTAP (jsc#PED-1942, gh#opensuse/wicked#1050, gh#opensuse/wicked#1051)
- `fsm`: remove children reference array from worker (gh#opensuse/wicked#1049)
- `ifxml`: migrate and generate lower configs/policies (gh#opensuse/wicked#1048)
- `fsm`: use refcount and array macros in worker and policy (gh#opensuse/wicked#1047)
- `route`: use refcounted array and fix error leaks (gh#opensuse/wicked#1046)
- `utils`: add support for refcounted objects in generic array (gh#openSUSE/wicked#1045)
The following package changes have been done:
- bind-utils-9.18.50-150600.3.32.1 updated
- cifs-utils-6.15-150400.3.24.1 updated
- cloud-init-config-suse-25.1.3-150400.15.10.2 updated
- cloud-init-25.1.3-150400.15.10.2 updated
- containerd-ctr-1.7.29-150000.146.1 updated
- containerd-1.7.29-150000.146.1 updated
- curl-8.14.1-150600.4.46.1 updated
- dmidecode-3.7-150400.16.14.1 updated
- dracut-059+suse.567.gf5cfeb7f7-150600.3.32.1 updated
- gawk-4.2.1-150000.3.6.1 updated
- glib2-tools-2.78.6-150600.4.38.1 updated
- glibc-locale-base-2.38-150600.14.52.1 updated
- glibc-2.38-150600.14.52.1 updated
- gpg2-2.4.4-150600.3.18.1 updated
- grub2-i386-pc-2.12-150600.8.55.1 updated
- grub2-snapper-plugin-2.12-150600.8.55.1 updated
- grub2-x86_64-efi-2.12-150600.8.55.1 updated
- grub2-x86_64-xen-2.12-150600.8.55.1 updated
- grub2-2.12-150600.8.55.1 updated
- gzip-1.10-150200.16.1 updated
- jq-1.6-150000.3.20.1 updated
- kernel-default-6.4.0-150600.23.130.1 updated
- kmod-29-150600.13.6.1 updated
- krb5-1.20.1-150600.11.19.1 updated
- libavahi-client3-0.8-150600.15.21.1 updated
- libavahi-common3-0.8-150600.15.21.1 updated
- libblkid1-2.39.3-150600.4.26.1 updated
- libcurl4-8.14.1-150600.4.46.1 updated
- libfdisk1-2.39.3-150600.4.26.1 updated
- libgcc_s1-15.3.0+git11272-150000.1.12.1 updated
- libgio-2_0-0-2.78.6-150600.4.38.1 updated
- libglib-2_0-0-2.78.6-150600.4.38.1 updated
- libgmodule-2_0-0-2.78.6-150600.4.38.1 updated
- libgobject-2_0-0-2.78.6-150600.4.38.1 updated
- libjq1-1.6-150000.3.20.1 updated
- libkmod2-29-150600.13.6.1 updated
- libmount1-2.39.3-150600.4.26.1 updated
- libnghttp2-14-1.40.0-150600.25.8.1 updated
- libopenssl1_1-1.1.1w-150600.5.35.2 updated
- libopenssl3-3.1.4-150600.5.59.1 updated
- libpng16-16-1.6.58-150600.3.23.1 updated
- libpython3_11-1_0-3.11.15-150600.3.65.1 updated
- libsmartcols1-2.39.3-150600.4.26.1 updated
- libsolv-tools-base-0.7.39-150600.8.24.1 updated
- libsqlite3-0-3.53.2-150000.3.42.1 updated
- libssh-config-0.9.8-150600.11.15.1 updated
- libssh4-0.9.8-150600.11.15.1 updated
- libstdc++6-15.3.0+git11272-150000.1.12.1 updated
- libsubid5-4.17.2-150600.17.21.1 updated
- libsystemd0-254.27-150600.4.71.2 updated
- libudev1-254.27-150600.4.71.2 updated
- libuuid1-2.39.3-150600.4.26.1 updated
- libxml2-2-2.10.3-150500.5.41.1 updated
- libxml2-tools-2.10.3-150500.5.41.1 updated
- libzypp-17.38.13-150600.3.92.1 updated
- login_defs-4.17.2-150600.17.21.1 updated
- net-tools-2.0+git20170221.479bb4a-150000.5.18.1 updated
- openssh-clients-9.6p1-150600.6.49.1 updated
- openssh-common-9.6p1-150600.6.49.1 updated
- openssh-server-config-disallow-rootlogin-9.6p1-150600.6.49.1 updated
- openssh-server-9.6p1-150600.6.49.1 updated
- openssh-9.6p1-150600.6.49.1 updated
- openssl-3-3.1.4-150600.5.59.1 updated
- pam-1.3.0-150000.6.89.1 updated
- perl-base-5.26.1-150300.17.23.1 updated
- perl-5.26.1-150300.17.23.1 updated
- python311-PyJWT-2.8.0-150400.8.13.1 updated
- python311-base-3.11.15-150600.3.65.1 updated
- python311-configobj-5.0.8-150400.12.7.1 updated
- python311-cryptography-41.0.3-150600.23.9.1 updated
- python311-idna-3.4-150400.11.13.1 updated
- python311-jsonpatch-1.32-150400.10.7.1 updated
- python311-jsonpointer-2.3-150400.11.7.1 updated
- python311-pyserial-3.5-150400.12.7.1 updated
- python311-urllib3-2.0.7-150400.7.33.1 updated
- python311-3.11.15-150600.3.65.1 updated
- rpcbind-0.2.3-150000.5.12.1 updated
- rpm-ndb-4.14.3-150400.59.19.1 updated
- rsyslog-module-relp-8.2406.0-150600.12.19.2 updated
- rsyslog-8.2406.0-150600.12.19.2 updated
- runc-1.3.6-150000.103.1 updated
- samba-client-libs-4.19.8+git.501.67274891bc-150600.3.29.1 updated
- scap-security-guide-0.1.80-150600.1.27 updated
- shadow-4.17.2-150600.17.21.1 updated
- supportutils-3.2.14.2-150600.3.12.1 updated
- suseconnect-ng-1.22.1-150600.3.21.1 updated
- sysconfig-netconfig-0.85.11-150200.18.1 updated
- sysconfig-0.85.11-150200.18.1 updated
- systemd-254.27-150600.4.71.2 updated
- tar-1.34-150000.3.42.1 updated
- timezone-2026c-150600.91.12.1 updated
- udev-254.27-150600.4.71.2 updated
- util-linux-systemd-2.39.3-150600.4.26.1 updated
- util-linux-2.39.3-150600.4.26.1 updated
- vim-data-common-9.2.0957-150500.20.64.1 updated
- vim-9.2.0957-150500.20.64.1 updated
- wicked-service-0.6.79-150600.11.20.1 updated
- wicked-0.6.79-150600.11.20.1 updated
- xen-libs-4.18.5_20-150600.3.53.3 updated
- xen-tools-domU-4.18.5_20-150600.3.53.3 updated
- zypper-1.14.98-150600.10.55.1 updated
More information about the sle-container-updates
mailing list