From null at suse.de Mon Aug 3 08:30:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 08:30:35 -0000 Subject: SUSE-SU-2026:3444-1: moderate: Security update for openssl-3 Message-ID: <178574583513.2189.2977488042315453383@b03e17030db4> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3444-1 Release Date: 2026-07-31T20:04:38Z Rating: moderate References: * bsc#1271712 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3444=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libopenssl-3-fips-provider-3.2.3-150700.5.40.1 * libopenssl3-3.2.3-150700.5.40.1 * libopenssl3-debuginfo-3.2.3-150700.5.40.1 * libopenssl-3-fips-provider-debuginfo-3.2.3-150700.5.40.1 * openssl-3-debugsource-3.2.3-150700.5.40.1 * openssl-3-3.2.3-150700.5.40.1 * libopenssl-3-devel-3.2.3-150700.5.40.1 * openssl-3-debuginfo-3.2.3-150700.5.40.1 * Basesystem Module 15-SP7 (x86_64) * libopenssl3-32bit-debuginfo-3.2.3-150700.5.40.1 * libopenssl-3-fips-provider-32bit-3.2.3-150700.5.40.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.2.3-150700.5.40.1 * libopenssl3-32bit-3.2.3-150700.5.40.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 08:31:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 08:31:18 -0000 Subject: SUSE-SU-2026:3443-1: moderate: Security update for openssl-1_0_0 Message-ID: <178574587863.2189.1992402211759795711@b03e17030db4> # Security update for openssl-1_0_0 Announcement ID: SUSE-SU-2026:3443-1 Release Date: 2026-07-31T19:27:36Z Rating: moderate References: * bsc#1261678 Cross-References: * CVE-2026-28390 CVSS scores: * CVE-2026-28390 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28390 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28390 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28390 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-1_0_0 fixes the following issue: * CVE-2026-28390: NULL pointer dereference during processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo (bsc#1261678). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3443=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3443=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3443=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3443=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3443=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3443=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3443=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3443=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3443=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl10-1.0.2p-150000.3.111.2 * libopenssl1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-1.0.2p-150000.3.111.2 * openssl-1_0_0-debugsource-1.0.2p-150000.3.111.2 * libopenssl10-debuginfo-1.0.2p-150000.3.111.2 * libopenssl1_0_0-hmac-1.0.2p-150000.3.111.2 * openssl-1_0_0-debuginfo-1.0.2p-150000.3.111.2 * libopenssl-1_0_0-devel-1.0.2p-150000.3.111.2 ## References: * https://www.suse.com/security/cve/CVE-2026-28390.html * https://bugzilla.suse.com/show_bug.cgi?id=1261678 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 08:31:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 08:31:57 -0000 Subject: SUSE-SU-2026:3442-1: important: Security update for rsyslog Message-ID: <178574591775.2189.7492733418288350918@b03e17030db4> # Security update for rsyslog Announcement ID: SUSE-SU-2026:3442-1 Release Date: 2026-07-31T19:22:06Z Rating: important References: * bsc#1272414 Cross-References: * CVE-2026-61548 CVSS scores: * CVE-2026-61548 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for rsyslog fixes the following issue: * CVE-2026-61548: parsing of crafted RFC 5424 messages in `mmpstrucdata` can lead to a stack buffer overflow (bsc#1272414). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3442=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3442=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3442=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rsyslog-module-gssapi-8.2406.0-150600.12.16.1 * rsyslog-debugsource-8.2406.0-150600.12.16.1 * rsyslog-module-snmp-8.2406.0-150600.12.16.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-udpspoof-8.2406.0-150600.12.16.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-pgsql-8.2406.0-150600.12.16.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-ossl-8.2406.0-150600.12.16.1 * rsyslog-module-mmnormalize-8.2406.0-150600.12.16.1 * rsyslog-module-mysql-8.2406.0-150600.12.16.1 * rsyslog-module-gtls-8.2406.0-150600.12.16.1 * rsyslog-module-relp-8.2406.0-150600.12.16.1 * rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-8.2406.0-150600.12.16.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-relp-debuginfo-8.2406.0-150600.12.16.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * rsyslog-module-snmp-8.2406.0-150600.12.16.1 * rsyslog-debugsource-8.2406.0-150600.12.16.1 * rsyslog-module-gssapi-8.2406.0-150600.12.16.1 * rsyslog-module-gcrypt-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-udpspoof-8.2406.0-150600.12.16.1 * rsyslog-module-omhttpfs-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-omamqp1-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-elasticsearch-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-gcrypt-8.2406.0-150600.12.16.1 * rsyslog-module-omhttpfs-8.2406.0-150600.12.16.1 * rsyslog-module-pgsql-8.2406.0-150600.12.16.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-kafka-8.2406.0-150600.12.16.1 * rsyslog-module-ossl-8.2406.0-150600.12.16.1 * rsyslog-module-mmnormalize-8.2406.0-150600.12.16.1 * rsyslog-module-mysql-8.2406.0-150600.12.16.1 * rsyslog-module-gtls-8.2406.0-150600.12.16.1 * rsyslog-module-omamqp1-8.2406.0-150600.12.16.1 * rsyslog-module-dbi-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-elasticsearch-8.2406.0-150600.12.16.1 * rsyslog-module-omtcl-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-diag-tools-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-diag-tools-8.2406.0-150600.12.16.1 * rsyslog-module-relp-8.2406.0-150600.12.16.1 * rsyslog-doc-8.2406.0-150600.12.16.1 * rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-dbi-8.2406.0-150600.12.16.1 * rsyslog-8.2406.0-150600.12.16.1 * rsyslog-module-kafka-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-omtcl-8.2406.0-150600.12.16.1 * rsyslog-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-relp-debuginfo-8.2406.0-150600.12.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rsyslog-module-gssapi-8.2406.0-150600.12.16.1 * rsyslog-debugsource-8.2406.0-150600.12.16.1 * rsyslog-module-snmp-8.2406.0-150600.12.16.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-udpspoof-8.2406.0-150600.12.16.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-pgsql-8.2406.0-150600.12.16.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-mmnormalize-8.2406.0-150600.12.16.1 * rsyslog-module-ossl-8.2406.0-150600.12.16.1 * rsyslog-module-mysql-8.2406.0-150600.12.16.1 * rsyslog-module-gtls-8.2406.0-150600.12.16.1 * rsyslog-module-relp-8.2406.0-150600.12.16.1 * rsyslog-module-snmp-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-8.2406.0-150600.12.16.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-debuginfo-8.2406.0-150600.12.16.1 * rsyslog-module-relp-debuginfo-8.2406.0-150600.12.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-61548.html * https://bugzilla.suse.com/show_bug.cgi?id=1272414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 08:32:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 08:32:57 -0000 Subject: SUSE-SU-2026:3441-1: important: Security update for GraphicsMagick Message-ID: <178574597719.2189.15583853820460425194@b03e17030db4> # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:3441-1 Release Date: 2026-07-31T19:20:11Z Rating: important References: * bsc#1268878 Cross-References: * CVE-2026-56379 CVSS scores: * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue: * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3441=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3441=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.42.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.42.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.42.1 * GraphicsMagick-devel-1.3.42-150600.3.42.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.42.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.42.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.42.1 * perl-GraphicsMagick-1.3.42-150600.3.42.1 * libGraphicsMagick3-config-1.3.42-150600.3.42.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.42.1 * GraphicsMagick-1.3.42-150600.3.42.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.42.1 * libGraphicsMagick++-devel-1.3.42-150600.3.42.1 * GraphicsMagick-debugsource-1.3.42-150600.3.42.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.42.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.42.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.42.1 * GraphicsMagick-devel-1.3.42-150600.3.42.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.42.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.42.1 * perl-GraphicsMagick-1.3.42-150600.3.42.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.42.1 * libGraphicsMagick3-config-1.3.42-150600.3.42.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.42.1 * GraphicsMagick-1.3.42-150600.3.42.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.42.1 * libGraphicsMagick++-devel-1.3.42-150600.3.42.1 * GraphicsMagick-debugsource-1.3.42-150600.3.42.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268878 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 08:33:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 08:33:55 -0000 Subject: SUSE-SU-2026:3440-1: important: Security update for tomcat Message-ID: <178574603507.2189.10530703620010902097@b03e17030db4> # Security update for tomcat Announcement ID: SUSE-SU-2026:3440-1 Release Date: 2026-07-31T18:34:28Z Rating: important References: * bsc#1271397 * bsc#1271398 Cross-References: * CVE-2026-59083 * CVE-2026-59084 CVSS scores: * CVE-2026-59083 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-59083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-59084 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-59084 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues: Update to Tomcat 9.0.120: Security issues fixed: * CVE-2026-59083: incorrect URL decoding in `RewriteValve` may allow security control bypass (bsc#1271397). * CVE-2026-59084: `EncryptInterceptor` requirements are not clearly documented (bsc#1271398). Other updates and bugfixes: * Tomcat 9.0.120: * Catalina * Fix: Avoid a race condition with concurrent lookups for a singleton JNDI resource. (markt) * Fix: Improve the performance of range validation for the default servlet. (markt) * Fix: Avoid NPE in RewriteValve. (markt) * Fix: 70127: Fix use of Bootstrap through reflection by restoring the public constructor. Use through scripts was not affected. (remm) * Fix: Restore ability to extend many element classes from AbstractAccessLogValve. (remm) * Fix: Align DIGEST authentication with RFC 7616 and require clients to provide a valid qop parameter. (markt) * Fix: Use Files API to create temporary docBase when antiLockingDocBase is enabled. (markt) * Fix: Improve validation of configuration when DataSourceRealm starts. (remm) * Fix: JAASRealm should do a logout if login does not fail outright but does not produce a Principal. (remm) * Fix: Various edge cases for SSI substitutions, quoting and escaping. * Fix: unintentional conversion of literal + to a space during rule processing in the RewriteValve. (markt) * Coyote * Fix: Avoid a potential JVM crash if a suitable version of Tomcat Native is not available when the connector is explicitly configured to use Tomcat Native with OpenSSL for TLS. (markt) * Fix: Correct a regression introduced in 9.0.119 that broke reading of some request bodies via a Reader. (markt) * Jasper * Fix: 70120: The fix for 69399 (itself a fix for a regression in the fix for 69333) was incomplete and tags that threw exceptions in doStartTag() and doEndTag() were incorrectly re-used. This fix prevents tags from being re-used if such an exception occurs. (markt) * Fix: 70135: Fix security classload regression. (remm) * Add: support for specifying Java 28 (with the value 28) as the compiler source and/or compiler target for JSP compilation. If used with an Eclipse JDT compiler version that does not support these values, a warning will be logged and the default will be used. (markt) * WebSocket * Fix: 70126: Fix WebSocket extension permessage-deflate so that it does not drop bytes if a compressed message inflates to more than the available buffer. Fix written by GPT-5.5. Test case written by Hironori Ichimiya. (markt) * Fix: Optimise WebSocket client processing of server responses during WebSocket HTTP upgrade process. (markt) * Other * Update: Byte Buddy to 1.18.9. (markt) * Update: UnboundID to 7.0.5. (markt) * Update: JaCoCo to 0.8.15. (markt) * Update: BND to 7.3.0. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3440=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3440=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * tomcat-9.0.120-3.174.1 * tomcat-admin-webapps-9.0.120-3.174.1 * tomcat-javadoc-9.0.120-3.174.1 * tomcat-jsp-2_3-api-9.0.120-3.174.1 * tomcat-el-3_0-api-9.0.120-3.174.1 * tomcat-servlet-4_0-api-9.0.120-3.174.1 * tomcat-lib-9.0.120-3.174.1 * tomcat-webapps-9.0.120-3.174.1 * tomcat-docs-webapp-9.0.120-3.174.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * tomcat-9.0.120-3.174.1 * tomcat-admin-webapps-9.0.120-3.174.1 * tomcat-javadoc-9.0.120-3.174.1 * tomcat-jsp-2_3-api-9.0.120-3.174.1 * tomcat-el-3_0-api-9.0.120-3.174.1 * tomcat-servlet-4_0-api-9.0.120-3.174.1 * tomcat-lib-9.0.120-3.174.1 * tomcat-webapps-9.0.120-3.174.1 * tomcat-docs-webapp-9.0.120-3.174.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59083.html * https://www.suse.com/security/cve/CVE-2026-59084.html * https://bugzilla.suse.com/show_bug.cgi?id=1271397 * https://bugzilla.suse.com/show_bug.cgi?id=1271398 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 08:34:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 08:34:35 -0000 Subject: SUSE-SU-2026:3439-1: important: Security update for google-guest-agent Message-ID: <178574607578.2189.173217401038590915@b03e17030db4> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:3439-1 Release Date: 2026-07-31T18:33:40Z Rating: important References: * bsc#1266603 * bsc#1272118 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272118). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3439=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-1.66.2 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266603 * https://bugzilla.suse.com/show_bug.cgi?id=1272118 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:30:41 -0000 Subject: SUSE-SU-2026:22996-1: important: Security update for ignition Message-ID: <178577464142.66.17821921018887125195@438c6482d549> # Security update for ignition Announcement ID: SUSE-SU-2026:22996-1 Release Date: 2026-07-30T05:09:58Z Rating: important References: * bsc#1266606 * bsc#1272059 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for ignition fixes the following issues: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266606). * CVE-2026-56852: golang.org/x/text/unicode/norm: handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272059). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1408=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * ignition-debuginfo-2.21.0-160000.5.1 * ignition-2.21.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266606 * https://bugzilla.suse.com/show_bug.cgi?id=1272059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:31:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:31:30 -0000 Subject: SUSE-SU-2026:22995-1: important: Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178577469047.66.11043111601267902982@438c6482d549> # Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22995-1 Release Date: 2026-07-30T04:40:12Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1405=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_5-default-debuginfo-16-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-16-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-16-160000.4.3 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:32:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:32:14 -0000 Subject: SUSE-SU-2026:22994-1: important: Security update for mcphost Message-ID: <178577473403.66.9116242605021478825@438c6482d549> # Security update for mcphost Announcement ID: SUSE-SU-2026:22994-1 Release Date: 2026-07-30T04:38:52Z Rating: important References: * bsc#1266572 * bsc#1272131 * bsc#1272488 Cross-References: * CVE-2026-39821 * CVE-2026-5160 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-5160 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-5160 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-5160 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for mcphost fixes the following issues: * CVE-2026-5160: github.com/yuin/goldmark/renderer: Cross-site Scripting due to improper URL validation (bsc#1272488). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266572). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1406=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * mcphost-0.34.0-160000.3.1 * mcphost-debuginfo-0.34.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-5160.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266572 * https://bugzilla.suse.com/show_bug.cgi?id=1272131 * https://bugzilla.suse.com/show_bug.cgi?id=1272488 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:33:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:33:00 -0000 Subject: SUSE-SU-2026:22993-1: important: Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178577478011.66.12056366314217774430@438c6482d549> # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22993-1 Release Date: 2026-07-30T04:17:24Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1404=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_1-debugsource-14-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-14-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-debuginfo-14-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:33:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:33:47 -0000 Subject: SUSE-SU-2026:22992-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178577482751.66.604963980184908727@438c6482d549> # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22992-1 Release Date: 2026-07-30T04:17:24Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1403=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_7-default-12-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-12-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:34:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:34:33 -0000 Subject: SUSE-SU-2026:22991-1: important: Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178577487341.66.4644446556014631659@438c6482d549> # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22991-1 Release Date: 2026-07-30T04:17:24Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1402=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_8-default-debuginfo-11-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-11-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:35:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:35:19 -0000 Subject: SUSE-SU-2026:22990-1: important: Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178577491959.66.2264864705192909235@438c6482d549> # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22990-1 Release Date: 2026-07-30T04:17:24Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1401=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_4-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-debuginfo-10-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:36:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:36:06 -0000 Subject: SUSE-SU-2026:22989-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178577496616.66.590614069737432519@438c6482d549> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22989-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1400=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_26-default-debuginfo-9-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-9-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:36:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:36:51 -0000 Subject: SUSE-SU-2026:22988-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178577501160.66.1563094277763474762@438c6482d549> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22988-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1399=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_27-default-debuginfo-8-160000.1.1 * kernel-livepatch-SLE16_Update_6-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:37:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:37:36 -0000 Subject: SUSE-SU-2026:22987-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178577505623.66.13327780456978745300@438c6482d549> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22987-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1398=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_28-default-7-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_7-debugsource-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:38:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:38:20 -0000 Subject: SUSE-SU-2026:22986-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178577510072.66.9971345161276382494@438c6482d549> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22986-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1397=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-6-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-6-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:39:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:39:05 -0000 Subject: SUSE-SU-2026:22985-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178577514522.66.11816623769679720228@438c6482d549> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22985-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1396=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_9-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:39:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:39:49 -0000 Subject: SUSE-SU-2026:22984-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178577518997.66.5917656281738634723@438c6482d549> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22984-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1395=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-5-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:40:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:40:34 -0000 Subject: SUSE-SU-2026:22983-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178577523472.66.8050688516368920943@438c6482d549> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22983-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1394=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_11-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-5-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-debuginfo-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:41:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:41:15 -0000 Subject: SUSE-SU-2026:22982-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 16) Message-ID: <178577527544.66.2081434800472711331@438c6482d549> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22982-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.33.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1393=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_33-default-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16_Update_12-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_33-default-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:41:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:41:56 -0000 Subject: SUSE-SU-2026:22981-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 16) Message-ID: <178577531624.66.6997709366115194800@438c6482d549> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22981-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1392=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_34-default-3-160000.1.2 * kernel-livepatch-SLE16_Update_13-debugsource-3-160000.1.2 * kernel-livepatch-6_12_0-160000_34-default-debuginfo-3-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:42:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:42:37 -0000 Subject: SUSE-SU-2026:22980-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178577535714.66.3156170446110856960@438c6482d549> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22980-1 Release Date: 2026-07-30T04:16:13Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1391=1 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_35-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16_Update_14-debugsource-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:43:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:43:15 -0000 Subject: SUSE-SU-2026:22979-1: important: Security update for libpng16 Message-ID: <178577539584.66.17203149641928844146@438c6482d549> # Security update for libpng16 Announcement ID: SUSE-SU-2026:22979-1 Release Date: 2026-07-29T15:47:13Z Rating: important References: * jsc#PED-16190 Affected Products: * SUSE Linux Micro 6.2 An update that contains one feature can now be installed. ## Description: This update for libpng16 fixes the following issues: Changes in libpng16: Version update to 1.6.58 [jsc#PED-16190] * see CHANGES for other upstream changes ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1390=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libpng16-16-1.6.58-160000.1.1 * libpng16-debugsource-1.6.58-160000.1.1 * libpng16-16-debuginfo-1.6.58-160000.1.1 ## References: * https://jira.suse.com/browse/PED-16190 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:44:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:44:04 -0000 Subject: SUSE-SU-2026:22978-1: important: Security update for openssh Message-ID: <178577544473.66.10882916815094007028@438c6482d549> # Security update for openssh Announcement ID: SUSE-SU-2026:22978-1 Release Date: 2026-07-29T08:10:11Z Rating: important References: * bsc#1271044 * bsc#1271046 * bsc#1271048 * bsc#1271049 * bsc#1271052 * bsc#1271053 * bsc#1271054 * bsc#1271055 Cross-References: * CVE-2026-59995 * CVE-2026-59996 * CVE-2026-59997 * CVE-2026-59998 * CVE-2026-59999 * CVE-2026-60000 * CVE-2026-60001 * CVE-2026-60002 CVSS scores: * CVE-2026-59995 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-59995 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-59995 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-59995 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-59996 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-59996 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-59996 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-59996 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-59997 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59997 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59997 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59997 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59998 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59998 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59998 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59998 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-59999 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59999 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59999 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59999 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60000 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-60000 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-60000 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60000 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-60001 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-60001 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-60001 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-60002 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-60002 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-60002 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L * CVE-2026-60002 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for openssh fixes the following issues: * CVE-2026-59995: sftp: location of downloaded files not properly constrained when `sftp server:/path .` is used with an attacker-controlled server (bsc#1271044). * CVE-2026-59996: scp: file placed in the parent directory of an intended target directory when copy occurs between two remote destinations (bsc#1271046). * CVE-2026-59997: sshd: `internal-sftp` command lines are silently truncated after the 9th argument (bsc#1271048). * CVE-2026-59998: sshd: undocumented security-relevant `GSSAPIStrictAcceptorCheck` behavior in Windows Active Directory is not documented (bsc#1271049). * CVE-2026-59999: sshd: `DisableForwarding=yes` does not override `PermitTunnel=yes` (bsc#1271052). * CVE-2026-60000: sshd: pre-authentication denial of service when GSSAPIAuthentication is enabled (bsc#1271053). * CVE-2026-60001: sshd: minimum authentication delay is not honored (bsc#1271054). * CVE-2026-60002: ssh: client-side use-after-free when a server changes its host key during a key reexchange (bsc#1271055). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1388=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * openssh-common-debuginfo-10.0p2-160000.7.1 * openssh-common-10.0p2-160000.7.1 * openssh-debuginfo-10.0p2-160000.7.1 * openssh-debugsource-10.0p2-160000.7.1 * openssh-server-10.0p2-160000.7.1 * openssh-clients-debuginfo-10.0p2-160000.7.1 * openssh-10.0p2-160000.7.1 * openssh-server-config-rootlogin-10.0p2-160000.7.1 * openssh-clients-10.0p2-160000.7.1 * openssh-server-debuginfo-10.0p2-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59995.html * https://www.suse.com/security/cve/CVE-2026-59996.html * https://www.suse.com/security/cve/CVE-2026-59997.html * https://www.suse.com/security/cve/CVE-2026-59998.html * https://www.suse.com/security/cve/CVE-2026-59999.html * https://www.suse.com/security/cve/CVE-2026-60000.html * https://www.suse.com/security/cve/CVE-2026-60001.html * https://www.suse.com/security/cve/CVE-2026-60002.html * https://bugzilla.suse.com/show_bug.cgi?id=1271044 * https://bugzilla.suse.com/show_bug.cgi?id=1271046 * https://bugzilla.suse.com/show_bug.cgi?id=1271048 * https://bugzilla.suse.com/show_bug.cgi?id=1271049 * https://bugzilla.suse.com/show_bug.cgi?id=1271052 * https://bugzilla.suse.com/show_bug.cgi?id=1271053 * https://bugzilla.suse.com/show_bug.cgi?id=1271054 * https://bugzilla.suse.com/show_bug.cgi?id=1271055 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:44:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:44:51 -0000 Subject: SUSE-SU-2026:22977-1: important: Security update for samba Message-ID: <178577549158.66.3898575586084762553@438c6482d549> # Security update for samba Announcement ID: SUSE-SU-2026:22977-1 Release Date: 2026-07-29T04:52:51Z Rating: important References: * bsc#1271469 * bsc#1271672 * bsc#1271673 * bsc#1271674 * bsc#1271675 * bsc#1271676 * bsc#1271677 Cross-References: * CVE-2026-15779 * CVE-2026-58216 * CVE-2026-58218 * CVE-2026-58221 * CVE-2026-58222 * CVE-2026-58224 * CVE-2026-6949 CVSS scores: * CVE-2026-15779 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15779 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15779 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58216 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58216 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58216 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58218 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-58218 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58218 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58222 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58222 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58224 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58224 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-6949 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6949 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves seven vulnerabilities can now be installed. ## Description: This update for samba fixes the following issues: * CVE-2026-6949: TSIG packet with crafted name compression can crash internal DNS server (bsc#1271672). * CVE-2026-15779: `pam_winbind` module with `mkhomedir` set allows `chown` of critical system paths without validation (bsc#1271469). * CVE-2026-58216: 6-byte heap OOB read in packet parser of the `kpasswd` service (bsc#1271674). * CVE-2026-58218: DNS TKEY negotiation stores unauthenticated GSS contexts in a fixed FIFO before authentication completes (bsc#1271675). * CVE-2026-58221: authenticated LDAP access to internal LDB special DNs permits domain takeover (bsc#1271676). * CVE-2026-58222: LDAP Compare filter injection and trusted-request confusion disclose protected attributes (bsc#1271677). * CVE-2026-58224: heap OOB read due to unchecked packet length fields in CTDB (bsc#1271673). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1386=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * samba-client-libs-4.22.9+git.538.af6cb4fb2e-160000.1.1 * libldb2-4.22.9+git.538.af6cb4fb2e-160000.1.1 * libldb2-debuginfo-4.22.9+git.538.af6cb4fb2e-160000.1.1 * samba-client-libs-debuginfo-4.22.9+git.538.af6cb4fb2e-160000.1.1 * samba-debuginfo-4.22.9+git.538.af6cb4fb2e-160000.1.1 * samba-debugsource-4.22.9+git.538.af6cb4fb2e-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15779.html * https://www.suse.com/security/cve/CVE-2026-58216.html * https://www.suse.com/security/cve/CVE-2026-58218.html * https://www.suse.com/security/cve/CVE-2026-58221.html * https://www.suse.com/security/cve/CVE-2026-58222.html * https://www.suse.com/security/cve/CVE-2026-58224.html * https://www.suse.com/security/cve/CVE-2026-6949.html * https://bugzilla.suse.com/show_bug.cgi?id=1271469 * https://bugzilla.suse.com/show_bug.cgi?id=1271672 * https://bugzilla.suse.com/show_bug.cgi?id=1271673 * https://bugzilla.suse.com/show_bug.cgi?id=1271674 * https://bugzilla.suse.com/show_bug.cgi?id=1271675 * https://bugzilla.suse.com/show_bug.cgi?id=1271676 * https://bugzilla.suse.com/show_bug.cgi?id=1271677 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:46:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:46:05 -0000 Subject: SUSE-SU-2026:22975-1: important: Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178577556507.66.15641074582644050380@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22975-1 Release Date: 2026-07-28T13:23:38Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1379=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_5-rt-debuginfo-14-160000.3.4 * kernel-livepatch-SLE16-RT_Update_0-debugsource-14-160000.3.4 * kernel-livepatch-6_12_0-160000_5-rt-14-160000.3.4 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:46:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:46:50 -0000 Subject: SUSE-SU-2026:22974-1: important: Security update for the Linux Kernel RT (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178577561074.66.16153202249972999410@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22974-1 Release Date: 2026-07-28T13:23:38Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1378=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_6-rt-13-160000.1.1 * kernel-livepatch-SLE16-RT_Update_1-debugsource-13-160000.1.1 * kernel-livepatch-6_12_0-160000_6-rt-debuginfo-13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:47:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:47:36 -0000 Subject: SUSE-SU-2026:22973-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178577565679.66.8009922230817980341@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22973-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1377=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_7-rt-debuginfo-11-160000.1.1 * kernel-livepatch-SLE16-RT_Update_2-debugsource-11-160000.1.1 * kernel-livepatch-6_12_0-160000_7-rt-11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:48:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:48:22 -0000 Subject: SUSE-SU-2026:22972-1: important: Security update for the Linux Kernel RT (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178577570270.66.15411554002369586471@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22972-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1376=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_8-rt-10-160000.1.1 * kernel-livepatch-6_12_0-160000_8-rt-debuginfo-10-160000.1.1 * kernel-livepatch-SLE16-RT_Update_3-debugsource-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:49:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:49:08 -0000 Subject: SUSE-SU-2026:22971-1: important: Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178577574881.66.9182332638949947511@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22971-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1375=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_4-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_9-rt-10-160000.1.1 * kernel-livepatch-6_12_0-160000_9-rt-debuginfo-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:49:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:49:54 -0000 Subject: SUSE-SU-2026:22970-1: important: Security update for the Linux Kernel RT (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178577579431.66.8639471357244690591@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22970-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1374=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_26-rt-9-160000.1.1 * kernel-livepatch-6_12_0-160000_26-rt-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16-RT_Update_5-debugsource-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:50:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:50:40 -0000 Subject: SUSE-SU-2026:22969-1: important: Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178577584093.66.5108087257361319295@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22969-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1262404 * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-23240 * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1373=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_27-rt-8-160000.1.1 * kernel-livepatch-6_12_0-160000_27-rt-debuginfo-8-160000.1.1 * kernel-livepatch-SLE16-RT_Update_6-debugsource-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:51:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:51:26 -0000 Subject: SUSE-SU-2026:22968-1: important: Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178577588610.66.5196921304813662372@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22968-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1372=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_28-rt-debuginfo-7-160000.1.1 * kernel-livepatch-6_12_0-160000_28-rt-7-160000.1.1 * kernel-livepatch-SLE16-RT_Update_7-debugsource-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:52:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:52:11 -0000 Subject: SUSE-SU-2026:22967-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178577593108.66.14542042703960457626@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22967-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1371=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_8-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_29-rt-debuginfo-6-160000.1.1 * kernel-livepatch-6_12_0-160000_29-rt-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:52:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:52:55 -0000 Subject: SUSE-SU-2026:22966-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178577597547.66.13659957876393513182@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22966-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1370=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_9-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-5-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-debuginfo-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:53:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:53:40 -0000 Subject: SUSE-SU-2026:22965-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178577602044.66.9286138338225449322@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22965-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1369=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_31-rt-5-160000.1.1 * kernel-livepatch-6_12_0-160000_31-rt-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16-RT_Update_10-debugsource-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:54:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:54:25 -0000 Subject: SUSE-SU-2026:22964-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178577606520.66.8300773620606042789@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22964-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1264060 * bsc#1266970 * bsc#1270060 * bsc#1271370 * bsc#1271648 Cross-References: * CVE-2026-31738 * CVE-2026-43038 * CVE-2026-46113 * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-31738 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31738 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31738 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-31738: vxlan: validate ND option lengths in vxlan_na_create (bsc#1264060). * CVE-2026-43038: ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() (bsc#1271648). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266970). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1368=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_11-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_32-rt-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_32-rt-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31738.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1264060 * https://bugzilla.suse.com/show_bug.cgi?id=1266970 * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271648 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:55:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:55:06 -0000 Subject: SUSE-SU-2026:22963-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 16) Message-ID: <178577610685.66.13259310549208861282@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22963-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.33.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1367=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_33-rt-3-160000.1.1 * kernel-livepatch-SLE16-RT_Update_12-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_33-rt-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:55:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:55:47 -0000 Subject: SUSE-SU-2026:22962-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 16) Message-ID: <178577614709.66.11064239905560718716@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22962-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1366=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_13-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_34-rt-3-160000.1.1 * kernel-livepatch-6_12_0-160000_34-rt-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:56:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:56:27 -0000 Subject: SUSE-SU-2026:22961-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178577618762.66.9581279168674023447@438c6482d549> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22961-1 Release Date: 2026-07-28T13:23:37Z Rating: important References: * bsc#1270060 * bsc#1271370 Cross-References: * CVE-2026-53359 * CVE-2026-53366 CVSS scores: * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53359 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270060). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1365=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_35-rt-3-160000.1.1 * kernel-livepatch-6_12_0-160000_35-rt-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16-RT_Update_14-debugsource-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://bugzilla.suse.com/show_bug.cgi?id=1270060 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:57:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:57:38 -0000 Subject: SUSE-SU-2026:22959-1: important: Security update for python313, python3 Message-ID: <178577625845.66.9122338162032328482@438c6482d549> # Security update for python313, python3 Announcement ID: SUSE-SU-2026:22959-1 Release Date: 2026-07-28T10:31:30Z Rating: important References: * bsc#1211301 * bsc#1258364 * bsc#1261969 * bsc#1261970 * bsc#1262098 * bsc#1262319 * bsc#1262654 * bsc#1263787 * jsc#PED-16123 Cross-References: * CVE-2021-4189 * CVE-2026-1502 * CVE-2026-3446 * CVE-2026-4786 * CVE-2026-6019 * CVE-2026-6100 CVSS scores: * CVE-2021-4189 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2021-4189 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2021-4189 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities, contains one feature and has two fixes can now be installed. ## Description: This update for python313, python3 fixes the following issues: Changes in python313: Update to 3.13.14: * Security * gh-151159: Bumps the OpenSSL version to 3.0.21 on Android. * gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. * gh-149835: shutil.move() now resolves symlinks via os.path.realpath() when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard. * gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186. * gh-87451: The ftplib module?s undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report. * gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink?s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter. * gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. * gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later. * gh-149017: Update bundled libexpat to version 2.8.0. * gh-90309: Base64-encode values when embedding cookies to JavaScript using the http.cookies.BaseCookie.js_output() method to avoid injection and escaping. (bsc#1262654, CVE-2026-6019) * gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. * gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, bz2.BZ2Decompressor, and internal zlib._ZlibDecompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer. (bsc#1262098, CVE-2026-6100, seems like it has been incompletely applied gh#python/cpython#151605) * gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262098, CVE-2026-6100). * gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing ?..? in the name (like ?foo..bar?) are no longer skipped. * gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. * gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method. (bsc#1261969, CVE-2026-1502) * Core and Builtins * gh-151112: Fix a crash in the compiler that could occur when running out of memory. * gh-151126: Fix a crash, when there?s no memory left on a device, which happened in: * code compilation - _winapi.CreateProcess() * Now these places raise proper MemoryError errors. * gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the sys.modules cache and create duplicate module objects. * gh-149156: Fix an intermittent crash after os.fork() when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process. * gh-149449: Fix a use-after-free crash when the unicodedata module was removed from sys.modules and garbage-collected between calls that decode \N{...} escapes or use the namereplace codec error handler. * gh-148450: Fix abc.register() so it invalidates type version tags for registered classes. * gh-150207: Fix a crash when a memory allocation fails during tokenizer initialization. A proper MemoryError is now raised instead. * gh-150107: asyncio: sendfile() and sock_sendfile() event loop methods now call file.seek(offset) if file has a seek() method, even if offset is 0 (default value). * gh-150146: Fix a crash on a complex type variable substitution. * from typing import TypeVar; memoryview[TypeVar("")][*typing.Mapping[..., ...]] used to fail due to missing NULL check on _unpack_args C function call. * gh-149590: Fix crash when faulthandler is imported more than once. * gh-149738: sqlite3: Disallow removing row_factory and text_factory attributes of a connection to prevent a crash on a query. * gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code used by -X perf_jit (Linux perf profiler integration). * gh-148820: Fix a race in _PyRawMutex on the free-threaded build where a Py_PARK_INTR return from _PySemaphore_Wait could let the waiter destroy its semaphore before the unlocking thread?s _PySemaphore_Wakeup completed, causing a fatal ReleaseSemaphore error. * gh-148653: Forbid marshalling recursive code objects which cannot be correctly unmarshalled. * gh-148390: Fix an undefined behavior in memoryview when using the native boolean format (?) in cast(). Previously, on some common platforms, calling memoryview(b).cast("?").tolist() incorrectly returned [False] instead of [True] for any even byte b. Patch by B?n?dikt Tran. * gh-148418: Fix a possible reference leak in a corrupted TYPE_CODE marshal stream. * gh-148222: Fix vectorcall support in types.GenericAlias when the underlying type does not support the vectorcall protocol. Fix possible leaks in types.GenericAlias and types.UnionType in case of memory error. * gh-145376: Fix reference leaks in various unusual error scenarios. * C API * gh-150907: Fix dynamic_annotations.h header file when built with C++ and Valgrind: add extern "C++" scope for the C++ template. Patch by Victor Stinner. * Build * gh-149351: Avoid possible broken macOS framework install names when DESTDIR is specified during builds. * gh-146475: Block Apple Clang from being used to build the JIT as it ships without required LLVM tools. * gh-148535: No longer use the gcc -fprofile-update=atomic flag on i686. The flag has been added to fix a random GCC internal error on PGO build (gh-145801) caused by corruption of profile data (.gcda files). The problem is that it makes the PGO build way slower (up to 47x slower) on i686. Since the GCC internal error was not seen on i686 so far, don?t use -fprofile-update=atomic on i686 anymore. Patch by Victor Stinner. * Library * gh-150913: Fix sqlite3.Blob slice assignment to raise TypeError and IndexError for type and size mismatches respectively, even when the target slice is empty. * gh-143008: Fix race conditions when re-initializing a io.TextIOWrapper object. * gh-150685: Update bundled pip to 26.1.2 * gh-150406: Fix a possible crash occurring during socket module initialization when the system is out of memory on platforms without a reentrant gethostbyname. * gh-150372: readline: Fix a potential crash during tab completion caused by an out-of-memory error during module initialization. * gh-150175: Fix race condition in unittest.mock.ThreadingMock where concurrent calls could lose increments to call_count and other attributes due to a missing lock in _increment_mock_call. * gh-84353: Preserve non-UTF-8 encoded filenames when appending to a zipfile.ZipFile. Previously, non-ASCII names stored in a legacy encoding (without the UTF-8 flag bit set) could be corrupted when the central directory was rewritten: they were decoded as cp437 and then re-stored as UTF-8. * gh-149995: Update various docstrings in typing. * gh-88726: The email package now uses standard MIME charset names ?gb2312? and ?big5? instead of non-standard names ?eucgb2312_cn? and ?big5_tw?. * gh-149571: Fix the C implementation of xml.etree.ElementTree.Element.itertext(): it no longer emits text for comments and processing instructions. * gh-149921: Fix reference leaks in error paths of the _interpchannels and _interpqueues extension modules. * gh-149801: Add IANA registered names and aliases with leading zeros before number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs. * gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is disabled * gh-112821: In the REPL, autocompletion might run arbitrary code in the getter of a descriptor. If that getter raised an exception, autocompletion would fail to present any options for the entire object. Autocompletion now works as expected for these objects. * gh-149388: Make asyncio.windows_utils.PipeHandle closing idempotent. * gh-149489: Fix ElementTree serialization to HTML. The content of elements ?xmp?, ?iframe?, ?noembed?, ?noframes?, and ?plaintext? is no longer escaped. The ?plaintext? element no longer have the closing tag. * gh-149377: Update bundled pip to 26.1.1 * gh-149231: In tomllib, the number of parts in TOML keys is now limited. * gh-149117: Fix runpy.run_module() and runpy.run_path() to set the name attribute on the ImportError they raise. * gh-149148: ensurepip: Upgrade bundled pip to 26.1. This version fixes the CVE 2026-3219 vulnerability. Patch by Victor Stinner. * gh-148093: Fix an out-of-bounds read of one byte in binascii.a2b_uu(). Raise binascii.Error, instead of reading past the buffer end. * gh-148914: Fix memoization of in-band PickleBuffer in the Python implementation of pickle. Previously, identical PickleBuffers did not preserve identity, and empty writable PickleBuffer memoized an empty bytearray object in place of b'', so the following references to b'' were unpickled as an empty bytearray object. * gh-138907: Support RFC 9309 in urllib.robotparser. * gh-148954: Fix XML injection vulnerability in xmlrpc.client.dumps() where the methodname was not being escaped before interpolation into the XML body. * gh-148801: xml.etree.ElementTree: Fix a crash in Element.**deepcopy** on deeply nested trees. * gh-148735: xml.etree.ElementTree: Fix a use-after-free in Element.findtext when the element tree is mutated concurrently during the search. * gh-146553: Fix infinite loop in typing.get_type_hints() when **wrapped** forms a cycle. Patch by Shamil Abdulaev. * gh-148508: An intermittent timing error when running SSL tests on iOS has been resolved. * gh-148518: If an email containing an address header that ended in an open double quote was parsed with a non-compat32 policy, accessing the username attribute of the mailbox accessed through that header object would result in an IndexError. It now correctly returns an empty string as the result. * gh-148370: configparser: prevent quadratic behavior when a ParsingError is raised after a parser fails to parse multiple lines. Patch by B?n?dikt Tran. * gh-148254: Use singular ?sec? instead of ?secs? in timeit verbose output for consistency with other time units. * gh-148192: email.generator.Generator._make_boundary could fail to detect a duplicate boundary string if linesep was not n. It now correctly detects boundary strings when linesep is rn as well. * gh-146313: Fix a deadlock in multiprocessing?s resource tracker where the parent process could hang indefinitely in os.waitpid() during interpreter shutdown if a child created via os.fork() still held the resource tracker?s pipe open. * gh-145831: Fix email.quoprimime.decode() leaving a stray \r when eol='\r\n' by stripping the full eol string instead of one character. * gh-145105: Fix crash in csv reader when iterating with a re-entrant iterator that calls next() on the same reader from within **next**. * gh-130750: Restore quoting of choices in argparse error messages for improved clarity and consistency with documentation. * gh-105936: Attempting to mutate non-field attributes of dataclasses with both frozen and slots being True now raises FrozenInstanceError instead of TypeError. Their non-dataclass subclasses can now freely mutate non-field attributes, and the original non-slotted class can be garbage collected. The fix also handles the case of an empty **class** cell on a function found within the class (gh-148947). * gh-142516: ssl: fix reference leaks in ssl.SSLContext objects. Patch by B?n?dikt Tran. * gh-142831: Fix a crash in the json module where a use-after-free could occur if the object being encoded is modified during serialization. * gh-140287: The asyncio REPL now handles exceptions when executing PYTHONSTARTUP scripts. Patch by Bartosz S?awecki. * gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by B?n?dikt Tran. * gh-132631: Fix ?I/O operation on closed file? when parsing JSON Lines file with JSON CLI. * gh-128110: Fix bug in the parsing of email address headers that could result in extraneous spaces in the decoded text when using a modern email policy. Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per section 6.2 (and consistent with existing parsing of unstructured headers like Subject). * gh-107398: Fix tarfile stream mode exception when process the file with the gzip extra field. * gh-123853: Update the table of Windows language code identifiers (LCIDs) used by locale.getdefaultlocale() on Windows to protocol version 16.0 (2024-04-23). * gh-70039: Fixed bug where smtplib.SMTP.starttls() could fail if smtplib.SMTP.connect() is called explicitly rather than implicitly. * gh-83281: email: improve handling trailing garbage in address lists to avoid throwing AttributeError in certain edge cases * gh-91099: imaplib.IMAP4.login() now raises exceptions with str instead of bytes. Patch by Florian Best. * IDLE * bpo-6699: Warn the user if a file will be overwritten when saving. * Documentation * gh-150319: Generic builtin and standard library types now document the meaning of their type parameters. * gh-148663: Document that calendar.IllegalMonthError is a subclass of both ValueError and IndexError since Python 3.12. * gh-146646: Document that glob.glob(), glob.iglob(), pathlib.Path.glob(), and pathlib.Path.rglob() silently suppress OSError exceptions raised from scanning the filesystem. * gh-109503: Fix documentation for shutil.move() on usage of os.rename() since nonatomic move might be used even if the files are on the same filesystem. Patch by Fang Li * Tests * gh-151130: Add more tests for PyWeakref_* C API. * gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it?s not supported. Patch by Victor Stinner. * Keep unversioned Python 3 development entry points in python3-devel: python313-devel no longer provides python3-devel and no longer owns libpython3.so, python3-config, python3.pc, or python3-embed.pc. Do not package versioned GIL pkg-config files in nogil-devel. Also, fix regular expressions in rpmlintrc. * Improve testing for the support of IPPROTO_UDPLITE, which could be not present although header files are. (bsc#1263787, gh#python/cpython!149081) * Add missing BR `crypto-policies-scripts` (need for the fix of bsc#1211301). * CVE-2026-6019: protect against HTML injection by Base64-encoding cookie values embedded in JS (bsc#1262654, gh#python/cpython#90309) * CVE-2026-1502: reject CR/LF in HTTP tunnel request headers (bsc#1261969, gh#python/cpython#146211) * CVE-2026-4786: fix webbrowser %action substitution bypass of dash-prefix check (bsc#1262319, gh#python/cpython#148169) * CVE-2026-6100: prevent dangling pointer, which can end in the use-after-free error (bsc#1262098, gh#python/cpython#148395) Changes in python3: * Provide explicitly also file dependencies /usr/bin/python3 and /usr/bin/pydoc3. break bootstrap build dependency cycle on primary python Break the cyclic build dependency loop between `python3` and `python313` during version upgrades (such as 3.13.13 to 3.13.14). Previously, `python3.spec` required `BuildRequires: %{primary_python}` (the versioned non-base interpreter package) and queried its version via `rpm -q` during spec file parsing. During upgrades, this blocked the build of `python3` because `%{primary_python}` (non-base) depended on `python3-base`, which demanded the new `python313-base` version. Since the unversioned compatibility package `python3` only creates unversioned symlinks (like `/usr/bin/python3`) and owns generic RPM macros, it does not actually require the versioned standard library modules (the non-base flavor) to build. This change allows `python3` to build successfully against the already built `python313-base` and `python313-devel` packages, breaking the circular dependency and enabling a clean upgrade path. * Let python3-devel explicitly provide pkgconfig(python3) and pkgconfig(python3-embed), matching its ownership of the unversioned pkg- config files. * Complete the transition of the unversioned python3 namespace (jsc#PED-16123, bsc#1258364). * Add missing Provides/Obsoletes for generic names. * Add macros.python3 (moved from python313). * Add BuildIgnore: gdb BuildRequires: python313-devel ? python313-devel owns /usr/share/gdb/auto-load/...libpython3.13...-gdb.py ? the currently published version of that file has #!/usr/bin/python3 ? RPM auto-generated Requires: python3-base on gdb ? OBS tries to install gdb into the build root and fails because python3-base is the package being built. * Correct the logic in the %pre scripts. * version of the package must be equal to the version of %primary_python * Initial packaging effort for the python3 superpackage. python3 is shipped as new package. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1359=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-base-debuginfo-3.13.14-160000.1.1 * python3-3.13.14-160000.1.1 * python313-curses-debuginfo-3.13.14-160000.1.1 * python313-3.13.14-160000.1.1 * libpython3_13-1_0-debuginfo-3.13.14-160000.1.1 * python313-core-debugsource-3.13.14-160000.1.1 * python313-debuginfo-3.13.14-160000.1.1 * python3-curses-3.13.14-160000.1.1 * python313-debugsource-3.13.14-160000.1.1 * python3-base-3.13.14-160000.1.1 * python313-base-3.13.14-160000.1.1 * python313-curses-3.13.14-160000.1.1 * libpython3_13-1_0-3.13.14-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2021-4189.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-3446.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://bugzilla.suse.com/show_bug.cgi?id=1211301 * https://bugzilla.suse.com/show_bug.cgi?id=1258364 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 * https://bugzilla.suse.com/show_bug.cgi?id=1263787 * https://jira.suse.com/browse/PED-16123 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:58:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:58:17 -0000 Subject: SUSE-SU-2026:3460-1: important: Security update for python-urwid Message-ID: <178577629734.66.16479174584741558438@438c6482d549> # Security update for python-urwid Announcement ID: SUSE-SU-2026:3460-1 Release Date: 2026-08-03T12:11:39Z Rating: important References: * bsc#1271868 Cross-References: * CVE-2026-9323 CVSS scores: * CVE-2026-9323 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9323 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9323 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-urwid fixes the following issue: * CVE-2026-9323: web session IDs generated by `Screen.start()` are not cryptographically secure (bsc#1271868). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3460=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3460=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3460=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3460=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3460=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3460=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3460=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3460=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3460=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3460=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3460=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python-urwid-debuginfo-2.0.1-150000.3.3.1 * python3-urwid-2.0.1-150000.3.3.1 * python3-urwid-debuginfo-2.0.1-150000.3.3.1 * python-urwid-debugsource-2.0.1-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9323.html * https://bugzilla.suse.com/show_bug.cgi?id=1271868 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:58:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:58:56 -0000 Subject: SUSE-SU-2026:3459-1: important: Security update for python3-dulwich Message-ID: <178577633639.66.8312868841221928734@438c6482d549> # Security update for python3-dulwich Announcement ID: SUSE-SU-2026:3459-1 Release Date: 2026-08-03T12:08:43Z Rating: important References: * bsc#1271525 Cross-References: * CVE-2026-38974 CVSS scores: * CVE-2026-38974 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-38974 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python3-dulwich fixes the following issue * CVE-2026-38974: Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py (bsc#1271525). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3459=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3459=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3459=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3459=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3459=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3459=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3459=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3459=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3459=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3459=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3459=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3459=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python3-dulwich-0.20.24-150400.11.1 * python3-dulwich-debuginfo-0.20.24-150400.11.1 * python3-dulwich-debugsource-0.20.24-150400.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-38974.html * https://bugzilla.suse.com/show_bug.cgi?id=1271525 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 16:59:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 16:59:57 -0000 Subject: SUSE-SU-2026:3458-1: important: Security update for vim Message-ID: <178577639772.66.7038578118790102806@438c6482d549> # Security update for vim Announcement ID: SUSE-SU-2026:3458-1 Release Date: 2026-08-03T12:01:11Z Rating: important References: * bsc#1268162 * bsc#1271193 * bsc#1271194 * bsc#1271195 * bsc#1271684 Cross-References: * CVE-2026-59856 * CVE-2026-59857 * CVE-2026-59858 CVSS scores: * CVE-2026-59856 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59856 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59856 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59856 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59857 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59857 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59857 ( NVD ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59857 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59858 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59858 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59858 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59858 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for vim fixes the following issues: Security issues fixed: * CVE-2026-59856: arbitrary code execution via PHP omni-completion (bsc#1271194). * CVE-2026-59857: out-of-bounds write in SAL soundfolding (bsc#1271195). * CVE-2026-59858: arbitrary code execution via C omni-completion (bsc#1271193). Non security issues fixed: * Guard suse.vimrc against re-entry to prevent an infinite sourcing loop (bsc#1271684). * Allow 'wrap' and 'linebreak' to be set from a modeline (bsc#1268162). Changes for vim: * Update to version 9.2.0780: * filetype detect missing from completion (9.2.0726). * popup images not rendered correctly when unfocused (9.2.0727). * filetype: supertux info pattern is relative to current dir (9.2.0728). * % skips parens on continued quoted lines (9.2.0729). * GTK4 GUI tabline is not updated (9.2.0730). * GTK4 GUI scrollbar size not updated when restoring a session (9.2.0731). * session: terminal restored using absolute columns/rows (9.2.0732). * GTK3: GUI slow on X11 since dropping the alpha channel (9.2.0733). * function pointer passed to STRNCMP() instead of a length (9.2.0734). * tests: comment test can be improved (9.2.0737). * completion: 'autocompletedelay' blocks the main loop and drops autocommands (9.2.0739). * GTK4: scrollbar wrongly displayed (9.2.0740). * complete_check() does not return TRUE for mapped input (9.2.0741). * filetype: SSH keys and related filetypes not recognized (9.2.0742). * string macros silently accept a size of the wrong type (9.2.0743). * popup_atcursor() closes immediately on white space (9.2.0744). * cscope: connection leak when growing the array fails (9.2.0747). * 'autocompletedelay' interferes with CTRL-G U (9.2.0748). * 'autocompletedelay' interferes with i_CTRL-K (9.2.0749). * completion: 'autocompletedelay' deferral leaks state (9.2.0750). * GTK3 GUI is slow under Wayland (9.2.0751). * GTK4: drag-and-drop does not support HTML (9.2.0752). * GTK GUI deferred redraw skipped on 'lazyredraw' (9.2.0753). * repeated completion length lookup in search_for_exact_line (9.2.0754). * 'autocomplete' behaves inconsistently when recording (9.2.0755). * session with multiple tabpages sets 'winminheight' to 0 (9.2.0756). * pum: no opacity when background not set for Popup menu group (9.2.0758). * some code for 'autocompletedelay' is no longer needed (9.2.0759). * compiler warning for using potentially uninitialized var (9.2.0760). * runtime(netrw): Unix: unable to open '\' file (9.2.0761). * duplicated sub-option name check in :set completion (9.2.0762). * compiler warning about unused function (9.2.0764). * popup: opacity popup over a terminal is not cleared when moved (9.2.0765). * quick_tab entries for empty letters point to the wrong index (9.2.0766). * legacy/vim9cmd modifiers do not set script version for options values (9.2.0767). * legacy/vim9cmd modifiers are not exclusive (9.2.0768). * conversion to utf-16be using iconv is inconsistent (9.2.0769). * dict_add_dict() has inconsistent ownership on failure (9.2.0770). * dict_add_list() has inconsistent ownership on failure (9.2.0771). * Vim9: null dereference inside alloc_type() (9.2.0772). * memory leak in evalfunc.c on alloc failure (9.2.0773). * memory leak in f_getscriptinfo() on alloc failure (9.2.0774). * memory leak in highlight_get_info() on alloc failure (9.2.0775). * memory leak in sign_getlist() on alloc failure (9.2.0776). * memory leak in add_defer() on alloc failure (9.2.0777). * memory leak in compile_dict() on alloc failure (9.2.0778). * memory leak in type_name_func() on alloc failure (9.2.0779). * memory leak in evalvars.c on alloc failure (9.2.0780). * Update to version 9.2.0725: * GTK: preedit font size is wrong for fractional point sizes (9.2.0532). * '[ mark moved to end of inserted text after CTRL-R CTRL-P paste (9.2.0533). * GTK UI does not support fullscreen mode (9.2.0534). * GTK4: mouse popup menu does not show up at mouse pointer (9.2.0537). * Cannot keep leading whitespace in %{} statusline expr (9.2.0538). * filetype: too many Bitbake include files are recognized (9.2.0539). * Vim9: endclass/endenum/endinterface can give errors (9.2.0541). * Vim9: wrong error when redeclaring a typed variable (9.2.0543). * GTK4: window blank after a resize or drag (9.2.0544). * popup: blending uses hardcoded fallback colors (9.2.0545). * configure: GTK4 build requires GTK >= 4.10 (9.2.0546). * "%v" in 'errorformat' is affected by 'tabstop' (9.2.0547). * GTK4: terminal and pty job output is not processed (9.2.0548). * Cursor wrong after autoindent strip is skipped (9.2.0549). * GTK4: 'mousehide' unhides cursor when switching tabs (9.2.0550). * filetype: Tolk files are not recognized (9.2.0551). * GTK4: F10 does nothing when the menubar is hidden (9.2.0552). * runtime(netrw): netrw rejects hostnames containing _ (9.2.0553). * GTK4: memory leak in free_menu() (9.2.0554). * too many strlen() in ex_substitute() (9.2.0555). * GTK4: scrollbars not shown and do not respond to clicks (9.2.0556). * filetype: Kawasaki Robots files are not recognized (9.2.0557). * filetype: Popcap Reanimation files are not recognized (9.2.0558). * filetype: Kaitai struct files are not recogonized (9.2.0559). * filetype: busybox shebang lines are not recognized (9.2.0560). * [security]: possible code execution with python3complete (9.2.0561). * filetype: SGF files are not recognized (9.2.0562). * GTK3/Wayland: crash with right mouse-button in tabline (9.2.0563). * GTK4: tabline does not respond to mouse clicks (9.2.0564). * [security]: out-of-bounds read in update_snapshot() (9.2.0565). * f duplicates window if do_ecmd() is aborted (9.2.0566). * dict function name allocation failure not handled (9.2.0567). * pythoncomplete: g:pythoncomplete_allow_import had no effect (9.2.0568). * out-of-bounds access in libvterm CSI 8 t resize (9.2.0569). * GTK4: mouse wheel scrolling does not work correctly (9.2.0570). * Vim9: memory leak in compile_nested_function() on failure (9.2.0571). * lines disappear with wrapping virtual text after a double-width char (9.2.0572). * Vim9: missing EX_WHOLE on some block keywords (9.2.0573). * popup_create() not blocked in secure/sandbox (9.2.0576). * GTK4: window resizing issues (9.2.0577). * GTK4: :unmenu does not remove entries from the menubar (9.2.0578). * :mksession, :mkview and :mkvimrc emit legacy Vim script (9.2.0579). * xxd: binary output is not colored with -R (9.2.0580). * After maximizing and deleting the quickfix buffer, window height is wrong (9.2.0581). * GTK4: compile error when XFONTSET is defined (9.2.0582). * completion: indent not ignored for fuzzy line completion (9.2.0583). * GTK4: missing UI features (9.2.0584). * line number wrong after undoing a deletion in quickfix buffer (9.2.0585). * Crash with TextPut autocmd when pasting in terminal buffer (9.2.0586). * GTK4: left scrollbar overlaps drawarea (9.2.0587). * GTK4: drawing area loses focus after closing a menubar popover (9.2.0588). * filetype: xinitrc files are not recognized (9.2.0589). * GTK4: drawing area loses focus shape on popup menu open (9.2.0590). * 'scrolljump' ignored when scrolling up (9.2.0591). * Error when restoring session with terminal window (9.2.0592). * :wqall ignores term_setkill() on running terminal buffers (9.2.0593). * Use-after-free with ":wqall" and a running terminal job (9.2.0594). * MS-Windows: Wrong buffer size calculation for gvimext (9.2.0595). * cmdline completion popup cannot be scrolled with the mouse (9.2.0596). * [security]: possible code execution with python complete (9.2.0597). * popup: title set with popup_setoptions() is not shown (9.2.0599). * clientserver method needs to be given as argument (9.2.0600). * matchfuzzypos() returns garbage positions for long candidates (9.2.0601). * popup: No opacity when background not set for Popup group (9.2.0602). * possible heap-buffer-overflow when resizing the GUI (9.2.0603). * GTK4: does not support all clipboard formats (9.2.0606). * GTK4: inputdialog() does not work as expected (9.2.0607). * popup_setoptions()/ch_setoptions() does not check secure mode (9.2.0608). * completion info popup cannot be scrolled with the keyboard (9.2.0609). * cindent: closing brace in a comment affects the next line's indent (9.2.0610). * MS-Windows: evim.exe not working with VIMDLL (9.2.0611). * Cannot render images in popup windows (9.2.0612). * opacity popup leaves stale cells (9.2.0614). * sixel encoder drops pixels on the right edge of shapes (9.2.0615). * GTK4: use-after-free on clipboard read timeout (9.2.0616). * GvimExt: does not support different runtime dirs (9.2.0617). * use-after-free in popup_getoptions() on dict_add() failure (9.2.0618). * integer overflow in popup image size validation (9.2.0619). * runtime(netrw): fix 2match pattern rebuild (9.2.0620). * 'autoindent' not stripped with virtualedit=onemore (9.2.0621). * str2blob() does not work with wide UTF-16 encoding (9.2.0622). * possible integer overflow in spellfile tree bounds check (9.2.0623). * C-N/C-P cannot be mapped in complete() completion (9.2.0624). * GTK4: Link error when Wayland is disabled (9.2.0625). * Vim9: illegal characters allowed in dict key names with dot notation (9.2.0626). * :vim9cmd source handles all scripts as Vim9 script (9.2.0627). * popup image: wrong overlap layering, kitty laggy (9.2.0628). * 0x80 and 0x9b byte not unescaped when check for valid abbr (9.2.0629). * popup images: kitty images output in GUI mode (9.2.0630). * DECRQM and SGR Mouse not supported in foot terminal (9.2.0631). * GTK4: no support for hardware-accelerated rendering (9.2.0632). * MS-Windows: No support for kitty graphics support in terminal (9.2.0633). * GTK4: no minimum resize limit (9.2.0634). * checking the syntax contains/cluster list is slow (9.2.0635). * popup image: stale pixels under RGBA animation frames (9.2.0636). * sixel: anti-aliased RGBA images render with visible outline (9.2.0637). * cannot return matches containing spaces from a custom completion (9.2.0638). * gq with 'formatprg' fails on an empty buffer (9.2.0639). * the "%" command jumps to parens and braces inside comments (9.2.0640). * GTK4: crash in gui_mch_menu_hidden() (9.2.0641). * statusline: buffer overflow with item groups (9.2.0642). * Missing Image ifdefs (9.2.0643). * popup image: duplicate sync-output code (9.2.0644). * Composing chars no longer accepted in end-id abbr (9.2.0645). * GTK3 GUI slow on HiDPI/4K with software rendering (9.2.0646). * matchfuzzypos() false exact match for long equal-length candidates (9.2.0647). * MS-Windows: Compile warnings (9.2.0648). * filetype: tf files sometimes incorrectly recognized (9.2.0649). * Vim aborts at startup when built with the example -O2 CFLAGS (9.2.0650). * completion: 'smartcase' doesn't work with 'longest' (9.2.0651). * popup: stale kitty image after clipwindow scrolls out of view (9.2.0652). * [security]: out-of-bounds write in tree_count_words() (9.2.0653). * GTK4: using uninitialised colors in gui_mch_init() (9.2.0654). * GTK4: missing NULL checks in vim_form_measure() (9.2.0655). * completion: using wrong tolower() in smartcase filtering (9.2.0656). * GTK4: missing menu when right-clicking in tabline (9.2.0657). * xxd: signed integer overflow in huntype() (9.2.0658). * GTK4: no balloon support in GUI (9.2.0659). * Dragging the scrollbar does not trigger WinScrolled (9.2.0660). * unintended wipe of Vim's temp dir, causes errors (9.2.0661). * [security] Stack out-of-bounds write in dump_prefixes() (9.2.0662). * [security]: runtime(netrw): code injection in local file deletion (9.2.0663). * GTK4: GTK critical error on exit printed (9.2.0665). * Terminal-Normal mode does not color empty lines with a background color (9.2.0666). * patch 9.2.0590 was wrong (9.2.0667). * GTK4: minimum horizontal size is too small (9.2.0668). * GTK4: toolbar can be improved (9.2.0669). * [security]: Out-of-bounds read with text properties (9.2.0670). * [security]: possible out-of-bounds read with sodium encrypted files (9.2.0671). * corrupted text property causes internal error (9.2.0672). * configure: clears dynamic ruby linker flags (9.2.0674). * MS-Windows: cannot switch to a buffer with '%' in its name (9.2.0676). * Cannot clear the alternate file register # (9.2.0677). * [security]: potential powershell code execution in zip.vim (9.2.0678). * [security]: Out-of-bounds read with text property virtual text (9.2.0679). * keytrans() doesn't replace '|' and '\' (9.2.0680). * configure: -lruby added even for a dynamic ruby build (9.2.0681). * Wrong dot-repeat when calling complete() while filtering completion (9.2.0682). * filetype completion mishandles finished sub options (9.2.0683). * :reg # does not display the value of the '#' register (9.2.0684). * clipboard.c does not get the Wayland CFLAGS on GTK2 (9.2.0685). * style: strcmp usage is inconsistent (9.2.0686). * popup_image_composites_frames() has improper if block scope (9.2.0687). * Terminal-Normal mode does not show the Visual selection on a colored empty line (9.2.0688). * the "%" command is slow on a long line with many slashes (9.2.0689). * Solaris: swap file names are too long (9.2.0690). * Solaris: Test_terminal_composing_unicode() fails (9.2.0691). * GTK2: build failure, popup images not drawn correctly (9.2.0692). * Solaris: some tests faiures due to Solaris peculiarities (9.2.0694). * Solaris: test_delete_temp_dir() fails because of missing flock (9.2.0695). * GTK4: A few issues with toolbar support (9.2.0696). * possible overflow when parsing CSI keys (9.2.0697). * [security]: Out-of-bounds write with soundfold() (9.2.0698). * [security]: possible code execution with python complete (9.2.0699). * configure: -lrt requirement for timer_create not detected (9.2.0700). * :windo and :tabdo create an extra window with 'winfixbuf' (9.2.0702). * session file does not store relative Vim9 autoload imports (9.2.0703). * GTK4: not handling mouse events (9.2.0704). * :delete # silently fails to update "# and clobbers "0 (9.2.0705). * completion: popup misplaced when text before it is concealed (9.2.0707). * Leaks in do_autocmd in error case (9.2.0708). * GTK4: a few minor issues (9.2.0709). * GTK4 GUI resize handling can be improved (9.2.0710). * leak in ins_compl_infercase_gettext() in error case (9.2.0711). * GTK4: dialogs not handling mnemonics correctly (9.2.0712). * completion: ruler not updated correctly when the popup menu is visible (9.2.0713). * Coverity warns for NULL deref (9.2.0714). * Coverity warns about copy/paste error in hl_blend_attr() (9.2.0715). * filetype: not all supertux files are recognized (9.2.0716). * :syn sync without an argument also lists syntax cluster (9.2.0718). * GTK4: default menu is lacking (9.2.0719). * GTK4: no support for browsefilter (9.2.0720). * serverlist() returns strings separated by \n (9.2.0721). * GTK4: find/replace dialog can be improved (9.2.0722). * term_start() does not support "noclose" (9.2.0723). * use-after-free when freeing exit_cb job on exit (9.2.0724). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3458=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3458=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3458=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3458=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3458=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3458=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3458=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3458=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3458=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3458=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * vim-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * openSUSE Leap 15.5 (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * vim-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * Basesystem Module 15-SP7 (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * vim-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * vim-debuginfo-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * vim-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * vim-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * vim-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * vim-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise Micro 5.5 (noarch) * vim-data-common-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * vim-9.2.0780-150500.20.61.2 * gvim-debuginfo-9.2.0780-150500.20.61.2 * vim-small-debuginfo-9.2.0780-150500.20.61.2 * vim-debuginfo-9.2.0780-150500.20.61.2 * vim-debugsource-9.2.0780-150500.20.61.2 * gvim-9.2.0780-150500.20.61.2 * vim-small-9.2.0780-150500.20.61.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * vim-data-9.2.0780-150500.20.61.2 * vim-data-common-9.2.0780-150500.20.61.2 ## References: * https://www.suse.com/security/cve/CVE-2026-59856.html * https://www.suse.com/security/cve/CVE-2026-59857.html * https://www.suse.com/security/cve/CVE-2026-59858.html * https://bugzilla.suse.com/show_bug.cgi?id=1268162 * https://bugzilla.suse.com/show_bug.cgi?id=1271193 * https://bugzilla.suse.com/show_bug.cgi?id=1271194 * https://bugzilla.suse.com/show_bug.cgi?id=1271195 * https://bugzilla.suse.com/show_bug.cgi?id=1271684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:00:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:00:54 -0000 Subject: SUSE-SU-2026:3457-1: important: Security update for openssl-1_1 Message-ID: <178577645444.66.13104805346266903528@438c6482d549> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:3457-1 Release Date: 2026-08-03T11:51:24Z Rating: important References: * bsc#1271712 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issue: * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3457=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3457=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3457=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3457=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3457=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3457=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3457=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3457=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3457=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-32bit-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-32bit-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-32bit-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.99.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * openSUSE Leap 15.4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-32bit-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.99.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libopenssl1_1-hmac-64bit-1.1.1l-150400.7.99.1 * libopenssl1_1-64bit-1.1.1l-150400.7.99.1 * libopenssl1_1-64bit-debuginfo-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-64bit-1.1.1l-150400.7.99.1 * openSUSE Leap 15.4 (noarch) * openssl-1_1-doc-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-32bit-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libopenssl1_1-1.1.1l-150400.7.99.1 * libopenssl-1_1-devel-1.1.1l-150400.7.99.1 * openssl-1_1-1.1.1l-150400.7.99.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.99.1 * libopenssl1_1-hmac-1.1.1l-150400.7.99.1 * openssl-1_1-debuginfo-1.1.1l-150400.7.99.1 * openssl-1_1-debugsource-1.1.1l-150400.7.99.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:01:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:01:49 -0000 Subject: SUSE-SU-2026:3456-1: important: Security update for perl-Net-DNS Message-ID: <178577650984.66.6135551472066518841@438c6482d549> # Security update for perl-Net-DNS Announcement ID: SUSE-SU-2026:3456-1 Release Date: 2026-08-03T11:50:44Z Rating: important References: * bsc#1272214 Cross-References: * CVE-2026-64194 CVSS scores: * CVE-2026-64194 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Net-DNS fixes the following issue: * CVE-2026-64194: RFC 1035 compression pointers are followed via recursion with no depth limit established, which can lead to DoS when specially crafted DNS packets are parsed (bsc#1272214). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3456=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3456=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3456=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3456=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3456=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3456=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3456=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3456=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3456=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3456=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3456=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * Basesystem Module 15-SP7 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * perl-Net-DNS-1.14-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64194.html * https://bugzilla.suse.com/show_bug.cgi?id=1272214 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:02:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:02:31 -0000 Subject: SUSE-SU-2026:3455-1: moderate: Security update for gawk Message-ID: <178577655143.66.18131240824712648004@438c6482d549> # Security update for gawk Announcement ID: SUSE-SU-2026:3455-1 Release Date: 2026-08-03T11:47:01Z Rating: moderate References: * bsc#1271351 * bsc#1271352 * bsc#1271354 Cross-References: * CVE-2026-40467 * CVE-2026-40468 * CVE-2026-40553 CVSS scores: * CVE-2026-40467 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40467 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40467 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40467 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40468 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L * CVE-2026-40468 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40468 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40468 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-40553 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-40553 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-40553 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40553 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for gawk fixes the following issues: * CVE-2026-40467: use-after-free in the `io.c` program file via the `do_getline_redir()` routine (bsc#1271351). * CVE-2026-40468: integer overflow in the `builtin.c` program file (bsc#1271352). * CVE-2026-40553: buffer overflow in the `extension/readdir.c` program file via the `ftype()` routine (bsc#1271354). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3455=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3455=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3455=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3455=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3455=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3455=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * gawk-debuginfo-4.2.1-150000.3.6.1 * gawk-debugsource-4.2.1-150000.3.6.1 * gawk-4.2.1-150000.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * gawk-debuginfo-4.2.1-150000.3.6.1 * gawk-debugsource-4.2.1-150000.3.6.1 * gawk-4.2.1-150000.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * gawk-debuginfo-4.2.1-150000.3.6.1 * gawk-debugsource-4.2.1-150000.3.6.1 * gawk-4.2.1-150000.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gawk-debuginfo-4.2.1-150000.3.6.1 * gawk-debugsource-4.2.1-150000.3.6.1 * gawk-4.2.1-150000.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gawk-debuginfo-4.2.1-150000.3.6.1 * gawk-debugsource-4.2.1-150000.3.6.1 * gawk-4.2.1-150000.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gawk-debuginfo-4.2.1-150000.3.6.1 * gawk-debugsource-4.2.1-150000.3.6.1 * gawk-4.2.1-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40467.html * https://www.suse.com/security/cve/CVE-2026-40468.html * https://www.suse.com/security/cve/CVE-2026-40553.html * https://bugzilla.suse.com/show_bug.cgi?id=1271351 * https://bugzilla.suse.com/show_bug.cgi?id=1271352 * https://bugzilla.suse.com/show_bug.cgi?id=1271354 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:03:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:03:10 -0000 Subject: SUSE-SU-2026:3454-1: moderate: Security update for perl-HTTP-Date Message-ID: <178577659012.66.11915418993220014078@438c6482d549> # Security update for perl-HTTP-Date Announcement ID: SUSE-SU-2026:3454-1 Release Date: 2026-08-03T11:45:34Z Rating: moderate References: * bsc#1271705 Cross-References: * CVE-2026-14741 CVSS scores: * CVE-2026-14741 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-14741 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14741 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTTP-Date fixes the following issue * CVE-2026-14741: CPU exhaustion due to polynomial regex backtracking in `parse_date` when processing specially crafted date strings (bsc#1271705). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3454=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * perl-HTTP-Date-6.02-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14741.html * https://bugzilla.suse.com/show_bug.cgi?id=1271705 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:04:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:04:04 -0000 Subject: SUSE-SU-2026:3453-1: important: Security update for java-11-openjdk Message-ID: <178577664425.66.2542725679724853068@438c6482d549> # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:3453-1 Release Date: 2026-08-03T11:45:12Z Rating: important References: * bsc#1264994 * bsc#1267355 * bsc#1272223 * bsc#1272224 * bsc#1272225 * bsc#1272227 * bsc#1272228 * bsc#1272233 * bsc#1272234 * bsc#1272235 * bsc#1272236 * bsc#1272237 Cross-References: * CVE-2026-41254 * CVE-2026-46917 * CVE-2026-46968 * CVE-2026-47010 * CVE-2026-47021 * CVE-2026-47027 * CVE-2026-47057 * CVE-2026-47058 * CVE-2026-47059 * CVE-2026-47063 * CVE-2026-60147 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46917 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46917 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46917 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46968 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46968 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-46968 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47010 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-47010 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47010 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-47021 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47021 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47021 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47027 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47027 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47057 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47057 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47057 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47058 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47058 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-47058 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-47059 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47059 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47059 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47063 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-47063 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-47063 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-60147 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-60147 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-60147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 11 vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: Upgrade to upstream tag jdk-11.0.32+9 (July 2026 CPU). Security issues fixed: * CVE-2026-41254: lcms: information disclosure and denial of service via integer overflow in `CubeSize` (bsc#1264994). * CVE-2026-46917: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1272223). * CVE-2026-46968: unauthenticated attacker with network access via TLS can gain unauthorized creation, deletion or modification access to critical data(bsc#1272224). * CVE-2026-47010: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert or delete access to some data (bsc#1272225). * CVE-2026-47021: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272227). * CVE-2026-47027: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272228). * CVE-2026-47057: unauthenticated attacker with network access via multiple protocols can cause a hang or frequently repeatable crash (bsc#1272233). * CVE-2026-47058: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272234). * CVE-2026-47059: unauthenticated attacker with network access via multiple protocols can cause a partial denial of service (bsc#1272235). * CVE-2026-47063: unauthenticated attacker with network access via multiple protocols can gain unauthorized creation, deletion or modification access to critical data (bsc#1272236). * CVE-2026-60147: unauthenticated attacker with network access via multiple protocols can gain unauthorized update, insert, delete and read access to some(bsc#1272237). Other updates and bugfixes: * Upgrade to upstream tag jdk-11.0.32+9 (July 2026 CPU): * JDK-8200566: DistributionPointFetcher fails to fetch CRLs if the DistributionPoints field contains more than one DistributionPoint and the first one fails * JDK-8242314: use reproducible random in vmTestbase shared code * JDK-8252412: [macos11] system dynamic libraries removed from filesystem * JDK-8275405: Linking error for classes with lambda template parameters and virtual functions * JDK-8275843: Random crashes while the UI code is executed * JDK-8286562: GCC 12 reports some compiler warnings * JDK-8287491: compiler/jvmci/errors/TestInvalidDebugInfo.java fails new assert: assert((uint)t < T_CONFLICT + 1) failed: invalid type # * JDK-8292177: InitialSecurityProperty JFR event * JDK-8293691: converting a defined BasicType value to a string should not crash the VM * JDK-8298730: Refactor subsystem_file_line_contents and add docs and tests * JDK-8314555: Build with mawk fails on Windows * JDK-8323672: Suppress unwanted autoconf added flags in CC and CXX * JDK-8324243: Compilation failures in java.desktop module with gcc 14 * JDK-8325766: Extend CertificateBuilder to create trust and end entity certificates programmatically * JDK-8327071: [Testbug] g-tests for cgroup leave files in /tmp on linux * JDK-8336498: [macos] [build]: install-file macro may run into permission denied error * JDK-8342858: Make target mac-jdk-bundle fails on chmod command * JDK-8347740: java/io/File/createTempFile/SpecialTempFile.java failing * JDK-8347811: Container detection code for cgroups v2 should use cgroup.controllers * JDK-8349988: Change cgroup version detection logic to not depend on /proc/cgroups * JDK-8350749: Upgrade JLine to 3.29.0 * JDK-8351359: OperatingSystemMXBean: values from getCpuLoad and getProcessCpuLoad are stale after 24.8 days (Windows) * JDK-8353714: [17u] Backport of 8347740 incomplete * JDK-8354878: File Leak in CgroupSubsystemFactory::determine_type of cgroupSubsystem_linux.cpp:300 * JDK-8355077: Compiler error at splashscreen_gif.c due to unterminated string initialization * JDK-8363966: GHA: Switch cross-compiling sysroots to Debian trixie * JDK-8365098: make/RunTests.gmk generates a wrong path to test artifacts on Alpine * JDK-8365660: test/jdk/sun/security/pkcs11/KeyAgreement/ tests skipped without SkipExceprion * JDK-8366159: SkippedException is treated as a pass for pkcs11/KeyStore, pkcs11/SecretKeyFactory and pkcs11/SecureRandom * JDK-8367766: [11u] src/jdk.crypto.ec/share/native/libsunec/ /impl/mpi.c:321:3: error: 'tmp.dp' may be used uninitialized * JDK-8368041: Enhance TLS certificate handling * JDK-8368670: Deadlock in JFR on event register + class load * JDK-8369032: Add test to ensure serialized ICC_Profile stores only necessary optional data * JDK-8369506: Bytecode rewriting causes Java heap corruption on AArch64 * JDK-8371559: Intermittent timeouts in test javax/net/ssl/Stapling/HttpsUrlConnClient.java * JDK-8372351: Add 2 WISeKey roots * JDK-8373275: Improve DTLS handshaking * JDK-8374058: Enhance JPEG handling * JDK-8374888: Implement internal test cache to help UserIterCount test performance * JDK-8375065: Update LCMS to 2.18 * JDK-8377158: Enhance XBM image support * JDK-8377167: javax/imageio/ReadAbortTest.java throw NPE when x11 unavailable * JDK-8377498: Improve HttpServer handling * JDK-8377833: Enhance Jar file processing * JDK-8378218: MSYS2 reports cygwin triplet causing bash configure failure * JDK-8378631: Update Zlib Data Compression Library to Version 1.3.2 * JDK-8378687: Improve delegation of HttpURLConnection * JDK-8378823: AIX build fails after zlib updated by JDK-8378631 * JDK-8379685: Bump update version of OpenJDK: 11.0.32 * JDK-8380672: Improve certification checking * JDK-8380947: Add pull request template * JDK-8381039: Enhance AWT ImagingLib * JDK-8381049: Enhance Jar handling * JDK-8381185: Improve Nashorn index handling * JDK-8381195: Enhance Dataview Implementation * JDK-8381519: Enhance Der Value Handling * JDK-8381551: DisabledCurve test fails on Windows after disabling SHA1 * JDK-8381796: Enhance Certificate parsing * JDK-8383175: (tz) Update Timezone Data to 2026b * JDK-8383354: Update LCMS to 2.19.1 * JDK-8383473: Follow on from tzdata2026b time change to include temporary hack BC time change * JDK-8384158: GHA: Downgrade Windows GHA runners to windows-2022 temporarily * JDK-8384495: Update Libpng to 1.6.58 * JDK-8384902: Update GIFlib to 6.1.3 * JDK-8386551: Windows build broken because of MSys2/Make update * JDK-8387976: [11u] Remove designator DEFAULT_PROMOTED_VERSION_PRE=ea for release 11.0.32 * Make post scripts less noisy (bsc#1267355). * Use `libalternatives` instead of `update-alternatives` for distributions where `libalternatives` is available. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3453=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3453=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3453=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3453=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3453=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3453=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3453=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3453=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3453=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3453=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3453=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3453=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-debuginfo-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-debugsource-11.0.32.0-150000.3.141.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-11-openjdk-11.0.32.0-150000.3.141.1 * java-11-openjdk-headless-11.0.32.0-150000.3.141.1 * java-11-openjdk-devel-11.0.32.0-150000.3.141.1 * java-11-openjdk-demo-11.0.32.0-150000.3.141.1 * SUSE Package Hub 15 15-SP7 (noarch) * java-11-openjdk-javadoc-11.0.32.0-150000.3.141.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-46917.html * https://www.suse.com/security/cve/CVE-2026-46968.html * https://www.suse.com/security/cve/CVE-2026-47010.html * https://www.suse.com/security/cve/CVE-2026-47021.html * https://www.suse.com/security/cve/CVE-2026-47027.html * https://www.suse.com/security/cve/CVE-2026-47057.html * https://www.suse.com/security/cve/CVE-2026-47058.html * https://www.suse.com/security/cve/CVE-2026-47059.html * https://www.suse.com/security/cve/CVE-2026-47063.html * https://www.suse.com/security/cve/CVE-2026-60147.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 * https://bugzilla.suse.com/show_bug.cgi?id=1267355 * https://bugzilla.suse.com/show_bug.cgi?id=1272223 * https://bugzilla.suse.com/show_bug.cgi?id=1272224 * https://bugzilla.suse.com/show_bug.cgi?id=1272225 * https://bugzilla.suse.com/show_bug.cgi?id=1272227 * https://bugzilla.suse.com/show_bug.cgi?id=1272228 * https://bugzilla.suse.com/show_bug.cgi?id=1272233 * https://bugzilla.suse.com/show_bug.cgi?id=1272234 * https://bugzilla.suse.com/show_bug.cgi?id=1272235 * https://bugzilla.suse.com/show_bug.cgi?id=1272236 * https://bugzilla.suse.com/show_bug.cgi?id=1272237 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:04:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:04:52 -0000 Subject: SUSE-SU-2026:3452-1: important: Security update for bind Message-ID: <178577669252.66.12015887223054006096@438c6482d549> # Security update for bind Announcement ID: SUSE-SU-2026:3452-1 Release Date: 2026-08-03T11:34:56Z Rating: important References: * bsc#1271982 * bsc#1271983 * bsc#1271984 * bsc#1271986 * bsc#1271987 * bsc#1271988 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2026-10723 * CVE-2026-10822 * CVE-2026-11331 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-12617 * CVE-2026-13204 * CVE-2026-13321 CVSS scores: * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10822 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10822 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-10822 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-12617 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12617 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12617 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves eight vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2026-10723: accepting incorrect child-zone NSEC3 records as valid can allow an attacker to forge authenticated NXDOMAIN responses for sibling zones (bsc#1271982). * CVE-2026-10822: storing a DNS key record with an invalid PRIVATEDNS algorithm identifier length can trigger a consistency check failure (bsc#1271983). * CVE-2026-11331: handling NAMETOOLONG error conditions incorrectly during RPZ wildcard CNAME processing can allow bypassing RPZ rules or triggering process exits (bsc#1271984). * CVE-2026-11622: DNSSEC validating resolver under a random subdomain attack can suffer from runaway memory usage exceeding max-cache-size and affecting response rate (bsc#1271986). * CVE-2026-11721: RRSIG with fewer labels than its containing zone when synth- from-dnssec is enabled can lead to wildcard generation (bsc#1271987). * CVE-2026-12617: delayed or specific CNAME/DNAME query responses combined with positive A record responses can trigger an assertion failure (bsc#1271988). * CVE-2026-13204: validating a domain covered by both NSEC and NSEC3 with an RRSIG for only one type can trigger an assertion failure (bsc#1271989). * CVE-2026-13321: NSEC records with a `Next Domain Name` pointing outside the signer's zone can allow cross-zone cache poisoning and authenticated denial- of-service responses (bsc#1271990). * Update to release 9.18.50: * Remove ineffective TCP fallback after repeated UDP timeouts. * Fall back to TCP on receipt of a UDP response with a mismatched query ID. * Fix DNS64 owner case after DNAME restart. * Clear REDIRECT flag when it isn't needed. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3452=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3452=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3452=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * bind-utils-9.18.50-150600.3.32.1 * bind-debuginfo-9.18.50-150600.3.32.1 * bind-9.18.50-150600.3.32.1 * bind-debugsource-9.18.50-150600.3.32.1 * bind-utils-debuginfo-9.18.50-150600.3.32.1 * openSUSE Leap 15.6 (noarch) * bind-doc-9.18.50-150600.3.32.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * bind-doc-9.18.50-150600.3.32.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * bind-utils-9.18.50-150600.3.32.1 * bind-debuginfo-9.18.50-150600.3.32.1 * bind-9.18.50-150600.3.32.1 * bind-debugsource-9.18.50-150600.3.32.1 * bind-utils-debuginfo-9.18.50-150600.3.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * bind-utils-9.18.50-150600.3.32.1 * bind-debuginfo-9.18.50-150600.3.32.1 * bind-9.18.50-150600.3.32.1 * bind-debugsource-9.18.50-150600.3.32.1 * bind-utils-debuginfo-9.18.50-150600.3.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * bind-doc-9.18.50-150600.3.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-10822.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-12617.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271983 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271988 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:06:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:06:01 -0000 Subject: SUSE-SU-2026:3451-1: important: Security update for xen Message-ID: <178577676149.66.15430767479270765993@438c6482d549> # Security update for xen Announcement ID: SUSE-SU-2026:3451-1 Release Date: 2026-08-03T11:33:32Z Rating: important References: * bsc#1271528 * bsc#1271530 * bsc#1271531 * bsc#1271532 * bsc#1271533 * bsc#1271534 * bsc#1271535 * bsc#1271537 * bsc#1271538 * bsc#1271539 * bsc#1271947 Cross-References: * CVE-2026-42493 * CVE-2026-42494 * CVE-2026-42495 * CVE-2026-62423 * CVE-2026-62424 * CVE-2026-62425 * CVE-2026-62426 * CVE-2026-62427 * CVE-2026-62428 * CVE-2026-62429 * CVE-2026-62430 * CVE-2026-62432 * CVE-2026-62433 * CVE-2026-62434 CVSS scores: * CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-42495 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62424 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62425 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62427 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 14 vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues * CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). * CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). * CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). * CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). * CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). * CVE-2026-62430: x86: out-of-bounds read in vRTC emulation (bsc#1271535). * CVE-2026-62432: evtchn: race between FIFO expand and reset (bsc#1271537). * CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). * CVE-2026-62434: PoD: don't try to reclaim special pages (bsc#1271539). * Pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3451=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3451=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * xen-tools-4.12.4_72-3.148.4 * xen-tools-debuginfo-4.12.4_72-3.148.4 * xen-tools-domU-debuginfo-4.12.4_72-3.148.4 * xen-libs-32bit-4.12.4_72-3.148.4 * xen-libs-debuginfo-4.12.4_72-3.148.4 * xen-libs-debuginfo-32bit-4.12.4_72-3.148.4 * xen-devel-4.12.4_72-3.148.4 * xen-libs-4.12.4_72-3.148.4 * xen-tools-domU-4.12.4_72-3.148.4 * xen-debugsource-4.12.4_72-3.148.4 * xen-doc-html-4.12.4_72-3.148.4 * xen-4.12.4_72-3.148.4 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * xen-tools-4.12.4_72-3.148.4 * xen-tools-debuginfo-4.12.4_72-3.148.4 * xen-tools-domU-debuginfo-4.12.4_72-3.148.4 * xen-libs-32bit-4.12.4_72-3.148.4 * xen-libs-debuginfo-4.12.4_72-3.148.4 * xen-libs-4.12.4_72-3.148.4 * xen-libs-debuginfo-32bit-4.12.4_72-3.148.4 * xen-devel-4.12.4_72-3.148.4 * xen-4.12.4_72-3.148.4 * xen-tools-domU-4.12.4_72-3.148.4 * xen-debugsource-4.12.4_72-3.148.4 * xen-doc-html-4.12.4_72-3.148.4 ## References: * https://www.suse.com/security/cve/CVE-2026-42493.html * https://www.suse.com/security/cve/CVE-2026-42494.html * https://www.suse.com/security/cve/CVE-2026-42495.html * https://www.suse.com/security/cve/CVE-2026-62423.html * https://www.suse.com/security/cve/CVE-2026-62424.html * https://www.suse.com/security/cve/CVE-2026-62425.html * https://www.suse.com/security/cve/CVE-2026-62426.html * https://www.suse.com/security/cve/CVE-2026-62427.html * https://www.suse.com/security/cve/CVE-2026-62428.html * https://www.suse.com/security/cve/CVE-2026-62429.html * https://www.suse.com/security/cve/CVE-2026-62430.html * https://www.suse.com/security/cve/CVE-2026-62432.html * https://www.suse.com/security/cve/CVE-2026-62433.html * https://www.suse.com/security/cve/CVE-2026-62434.html * https://bugzilla.suse.com/show_bug.cgi?id=1271528 * https://bugzilla.suse.com/show_bug.cgi?id=1271530 * https://bugzilla.suse.com/show_bug.cgi?id=1271531 * https://bugzilla.suse.com/show_bug.cgi?id=1271532 * https://bugzilla.suse.com/show_bug.cgi?id=1271533 * https://bugzilla.suse.com/show_bug.cgi?id=1271534 * https://bugzilla.suse.com/show_bug.cgi?id=1271535 * https://bugzilla.suse.com/show_bug.cgi?id=1271537 * https://bugzilla.suse.com/show_bug.cgi?id=1271538 * https://bugzilla.suse.com/show_bug.cgi?id=1271539 * https://bugzilla.suse.com/show_bug.cgi?id=1271947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:06:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:06:40 -0000 Subject: SUSE-SU-2026:3450-1: moderate: Security update for containerd Message-ID: <178577680038.66.161475271879198917@438c6482d549> # Security update for containerd Announcement ID: SUSE-SU-2026:3450-1 Release Date: 2026-08-03T11:26:55Z Rating: moderate References: * bsc#1262266 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-35469 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues: * CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3450=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3450=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3450=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3450=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3450=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3450=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3450=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.142.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.142.1 * containerd-ctr-1.7.29-150000.142.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.142.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.142.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.142.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.142.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.142.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:07:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:07:19 -0000 Subject: SUSE-SU-2026:3449-1: important: Security update for rrdtool Message-ID: <178577683945.66.1978589112413957811@438c6482d549> # Security update for rrdtool Announcement ID: SUSE-SU-2026:3449-1 Release Date: 2026-08-03T11:20:58Z Rating: important References: * bsc#1267243 Cross-References: * CVE-2026-43958 CVSS scores: * CVE-2026-43958 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43958 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43958 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for rrdtool fixes the following issue * CVE-2026-43958: stack buffer overflow in `rrdcached` `handle_request_create()` can lead to local privilege escalation via unbounded DS/RRA arguments (bsc#1267243). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3449=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3449=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3449=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3449=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3449=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3449=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3449=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3449=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-1.7.0-150000.6.6.1 * perl-rrdtool-1.7.0-150000.6.6.1 * librrd8-1.7.0-150000.6.6.1 * librrd8-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debuginfo-1.7.0-150000.6.6.1 * rrdtool-debugsource-1.7.0-150000.6.6.1 * rrdtool-devel-1.7.0-150000.6.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43958.html * https://bugzilla.suse.com/show_bug.cgi?id=1267243 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 17:08:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 17:08:03 -0000 Subject: SUSE-SU-2026:3448-1: important: Security update for nginx Message-ID: <178577688329.66.11492429928482652190@438c6482d549> # Security update for nginx Announcement ID: SUSE-SU-2026:3448-1 Release Date: 2026-08-03T11:17:08Z Rating: important References: * bsc#1267525 * bsc#1268492 * bsc#1268495 * bsc#1271514 Cross-References: * CVE-2026-42055 * CVE-2026-42533 * CVE-2026-48142 CVSS scores: * CVE-2026-42055 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42055 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42533 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42533 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42533 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42533 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48142 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-48142 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48142 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for nginx fixes the following issues: * CVE-2026-42055: heap buffer overflow in the `ngx_http_proxy_v2_module` and `ngx_http_grpc_module` modules (bsc#1268492). * CVE-2026-42533: heap buffer overflow in the `map` directive and regex matching (bsc#1271514). * CVE-2026-48142: heap buffer overread in the `ngx_http_charset_module` module (bsc#1268495). * Remote denial of service via the HTTP/2 bomb exploit (bsc#1267525). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3448=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3448=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3448=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3448=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3448=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3448=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3448=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3448=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3448=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.25.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * openSUSE Leap 15.4 (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * nginx-source-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * nginx-debuginfo-1.21.5-150400.3.25.1 * nginx-1.21.5-150400.3.25.1 * nginx-debugsource-1.21.5-150400.3.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * nginx-source-1.21.5-150400.3.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42055.html * https://www.suse.com/security/cve/CVE-2026-42533.html * https://www.suse.com/security/cve/CVE-2026-48142.html * https://bugzilla.suse.com/show_bug.cgi?id=1267525 * https://bugzilla.suse.com/show_bug.cgi?id=1268492 * https://bugzilla.suse.com/show_bug.cgi?id=1268495 * https://bugzilla.suse.com/show_bug.cgi?id=1271514 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 20:32:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 20:32:44 -0000 Subject: SUSE-SU-2026:3463-1: moderate: Security update for libssh Message-ID: <178578916445.99.4479260076609415195@343aec21e6f1> # Security update for libssh Announcement ID: SUSE-SU-2026:3463-1 Release Date: 2026-08-03T12:18:59Z Rating: moderate References: * bsc#1272164 * bsc#1272165 * bsc#1272166 * bsc#1272167 * bsc#1272168 * bsc#1272169 * bsc#1272171 Cross-References: * CVE-2026-59843 * CVE-2026-59844 * CVE-2026-59845 * CVE-2026-59846 * CVE-2026-59847 * CVE-2026-59848 * CVE-2026-59850 CVSS scores: * CVE-2026-59843 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59843 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59843 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59844 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59844 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59845 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-59845 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59845 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2026-59846 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59846 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59846 ( NVD ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59847 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-59847 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-59847 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59847 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59848 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59848 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59848 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59850 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59850 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libssh fixes the following issues: * CVE-2026-59843: denial of service via zero advertised channel packet size (bsc#1272164). * CVE-2026-59844: denial of service via oversized SFTP read length (bsc#1272165). * CVE-2026-59845: denial of service via unchecked ProxyCommand fork() failure (bsc#1272166). * CVE-2026-59846: information disclosure via ProxyCommand %r username expansion (bsc#1272167). * CVE-2026-59847: integrity downgrade via OpenSSL AES-GCM tag verification (bsc#1272168). * CVE-2026-59848: denial of service via SFTP responses with unknown request IDs (bsc#1272169). * CVE-2026-59850: use-after-free via data callbacks on closed channels (bsc#1272171). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3463=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3463=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3463=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3463=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3463=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3463=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3463=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3463=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3463=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3463=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3463=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3463=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3463=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3463=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * openSUSE Leap 15.4 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libssh4-64bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-64bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libssh-devel-0.9.8-150400.3.20.1 * libssh-config-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libssh4-32bit-debuginfo-0.9.8-150400.3.20.1 * libssh4-32bit-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libssh-config-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libssh-config-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libssh-config-0.9.8-150400.3.20.1 * libssh-debugsource-0.9.8-150400.3.20.1 * libssh4-debuginfo-0.9.8-150400.3.20.1 * libssh4-0.9.8-150400.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59843.html * https://www.suse.com/security/cve/CVE-2026-59844.html * https://www.suse.com/security/cve/CVE-2026-59845.html * https://www.suse.com/security/cve/CVE-2026-59846.html * https://www.suse.com/security/cve/CVE-2026-59847.html * https://www.suse.com/security/cve/CVE-2026-59848.html * https://www.suse.com/security/cve/CVE-2026-59850.html * https://bugzilla.suse.com/show_bug.cgi?id=1272164 * https://bugzilla.suse.com/show_bug.cgi?id=1272165 * https://bugzilla.suse.com/show_bug.cgi?id=1272166 * https://bugzilla.suse.com/show_bug.cgi?id=1272167 * https://bugzilla.suse.com/show_bug.cgi?id=1272168 * https://bugzilla.suse.com/show_bug.cgi?id=1272169 * https://bugzilla.suse.com/show_bug.cgi?id=1272171 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 20:33:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 20:33:56 -0000 Subject: SUSE-SU-2026:3462-1: important: Security update for xen Message-ID: <178578923683.99.5460870309573950159@343aec21e6f1> # Security update for xen Announcement ID: SUSE-SU-2026:3462-1 Release Date: 2026-08-03T12:17:20Z Rating: important References: * bsc#1271528 * bsc#1271530 * bsc#1271531 * bsc#1271532 * bsc#1271533 * bsc#1271534 * bsc#1271535 * bsc#1271536 * bsc#1271537 * bsc#1271538 * bsc#1271539 * bsc#1271947 Cross-References: * CVE-2026-42493 * CVE-2026-42494 * CVE-2026-42495 * CVE-2026-62423 * CVE-2026-62424 * CVE-2026-62425 * CVE-2026-62426 * CVE-2026-62427 * CVE-2026-62428 * CVE-2026-62429 * CVE-2026-62430 * CVE-2026-62431 * CVE-2026-62432 * CVE-2026-62433 * CVE-2026-62434 CVSS scores: * CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-42495 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62424 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62425 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62427 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62431 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62431 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues * CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). * CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). * CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). * CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). * CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). * CVE-2026-62430: x86: out-of-bounds read in vRTC emulation (bsc#1271535). * CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). * CVE-2026-62432: evtchn: race between FIFO expand and reset (bsc#1271537). * CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). * CVE-2026-62434: PoD: don't try to reclaim special pages (bsc#1271539). * Pygrub is only supported in de-privileged mode (XSA-508) (bsc#1271947). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3462=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3462=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3462=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3462=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3462=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3462=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3462=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3462=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3462=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * xen-libs-4.16.7_12-150400.4.89.3 * xen-tools-debuginfo-4.16.7_12-150400.4.89.3 * xen-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-devel-4.16.7_12-150400.4.89.3 * xen-tools-4.16.7_12-150400.4.89.3 * xen-tools-domU-debuginfo-4.16.7_12-150400.4.89.3 * xen-tools-domU-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * xen-libs-4.16.7_12-150400.4.89.3 * xen-tools-debuginfo-4.16.7_12-150400.4.89.3 * xen-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-devel-4.16.7_12-150400.4.89.3 * xen-tools-4.16.7_12-150400.4.89.3 * xen-tools-domU-debuginfo-4.16.7_12-150400.4.89.3 * xen-tools-domU-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * xen-tools-xendomains-wait-disk-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-libs-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-libs-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * openSUSE Leap 15.4 (i586 x86_64) * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * xen-libs-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-tools-domU-4.16.7_12-150400.4.89.3 * xen-tools-domU-debuginfo-4.16.7_12-150400.4.89.3 * xen-devel-4.16.7_12-150400.4.89.3 * openSUSE Leap 15.4 (x86_64) * xen-tools-debuginfo-4.16.7_12-150400.4.89.3 * xen-libs-32bit-debuginfo-4.16.7_12-150400.4.89.3 * xen-doc-html-4.16.7_12-150400.4.89.3 * xen-4.16.7_12-150400.4.89.3 * xen-libs-32bit-4.16.7_12-150400.4.89.3 * xen-tools-4.16.7_12-150400.4.89.3 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * xen-tools-debuginfo-4.16.7_12-150400.4.89.3 * xen-libs-4.16.7_12-150400.4.89.3 * xen-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-devel-4.16.7_12-150400.4.89.3 * xen-tools-4.16.7_12-150400.4.89.3 * xen-tools-domU-debuginfo-4.16.7_12-150400.4.89.3 * xen-tools-domU-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-libs-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-libs-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * xen-libs-debuginfo-4.16.7_12-150400.4.89.3 * xen-libs-4.16.7_12-150400.4.89.3 * xen-tools-debuginfo-4.16.7_12-150400.4.89.3 * xen-4.16.7_12-150400.4.89.3 * xen-debugsource-4.16.7_12-150400.4.89.3 * xen-devel-4.16.7_12-150400.4.89.3 * xen-tools-domU-4.16.7_12-150400.4.89.3 * xen-tools-domU-debuginfo-4.16.7_12-150400.4.89.3 * xen-tools-4.16.7_12-150400.4.89.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_12-150400.4.89.3 ## References: * https://www.suse.com/security/cve/CVE-2026-42493.html * https://www.suse.com/security/cve/CVE-2026-42494.html * https://www.suse.com/security/cve/CVE-2026-42495.html * https://www.suse.com/security/cve/CVE-2026-62423.html * https://www.suse.com/security/cve/CVE-2026-62424.html * https://www.suse.com/security/cve/CVE-2026-62425.html * https://www.suse.com/security/cve/CVE-2026-62426.html * https://www.suse.com/security/cve/CVE-2026-62427.html * https://www.suse.com/security/cve/CVE-2026-62428.html * https://www.suse.com/security/cve/CVE-2026-62429.html * https://www.suse.com/security/cve/CVE-2026-62430.html * https://www.suse.com/security/cve/CVE-2026-62431.html * https://www.suse.com/security/cve/CVE-2026-62432.html * https://www.suse.com/security/cve/CVE-2026-62433.html * https://www.suse.com/security/cve/CVE-2026-62434.html * https://bugzilla.suse.com/show_bug.cgi?id=1271528 * https://bugzilla.suse.com/show_bug.cgi?id=1271530 * https://bugzilla.suse.com/show_bug.cgi?id=1271531 * https://bugzilla.suse.com/show_bug.cgi?id=1271532 * https://bugzilla.suse.com/show_bug.cgi?id=1271533 * https://bugzilla.suse.com/show_bug.cgi?id=1271534 * https://bugzilla.suse.com/show_bug.cgi?id=1271535 * https://bugzilla.suse.com/show_bug.cgi?id=1271536 * https://bugzilla.suse.com/show_bug.cgi?id=1271537 * https://bugzilla.suse.com/show_bug.cgi?id=1271538 * https://bugzilla.suse.com/show_bug.cgi?id=1271539 * https://bugzilla.suse.com/show_bug.cgi?id=1271947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Aug 3 20:35:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 03 Aug 2026 20:35:02 -0000 Subject: SUSE-SU-2026:3461-1: important: Security update for perl-DBI Message-ID: <178578930216.99.8669405756992309800@343aec21e6f1> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:3461-1 Release Date: 2026-08-03T12:13:58Z Rating: important References: * bsc#1271017 * bsc#1271018 * bsc#1271399 * bsc#1271458 * bsc#1271459 * bsc#1271629 * bsc#1271822 Cross-References: * CVE-2026-14380 * CVE-2026-14740 * CVE-2026-15043 * CVE-2026-15392 * CVE-2026-60081 * CVE-2026-60082 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-15043 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15043 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-15043 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15392 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-15392 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-60081 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60081 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-60082 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-60082 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for perl-DBI fixes the following issues: * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). * CVE-2026-15043: incorrect predicate evaluation in `DBI:SQL:Nano` can lead to bypass of file-backed filters (bsc#1271399). * CVE-2026-15392: missing checks to ensure the table file is not a symlink to an untrusted location in `DBD::File` allows for arbitrary file reads and writes (bsc#1271629). * CVE-2026-60081: no limiting of the path index in profile parser of `DBI:ProfileData` can enable small-file memory-amplification DoS (bsc#1271458). * CVE-2026-60082: out-of-bounds access in `_set_fbav` when a statement handle has zero fields but a non-empty row can lead to a process crash (bsc#1271459). Changes for perl-DBI: * Missing method dependency in the path-containment guard can cause security check failures and functional regressions when handling table symlinks (bsc#1271822). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3461=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3461=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-DBI-debuginfo-1.628-5.21.1 * perl-DBI-1.628-5.21.1 * perl-DBI-debugsource-1.628-5.21.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debuginfo-1.628-5.21.1 * perl-DBI-1.628-5.21.1 * perl-DBI-debugsource-1.628-5.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://www.suse.com/security/cve/CVE-2026-15043.html * https://www.suse.com/security/cve/CVE-2026-15392.html * https://www.suse.com/security/cve/CVE-2026-60081.html * https://www.suse.com/security/cve/CVE-2026-60082.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 * https://bugzilla.suse.com/show_bug.cgi?id=1271399 * https://bugzilla.suse.com/show_bug.cgi?id=1271458 * https://bugzilla.suse.com/show_bug.cgi?id=1271459 * https://bugzilla.suse.com/show_bug.cgi?id=1271629 * https://bugzilla.suse.com/show_bug.cgi?id=1271822 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:30:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:30:46 -0000 Subject: SUSE-SU-2026:3477-1: important: Security update for bind Message-ID: <178583224697.6741.17281273647336959791@dac66d42c24b> # Security update for bind Announcement ID: SUSE-SU-2026:3477-1 Release Date: 2026-08-03T16:58:45Z Rating: important References: * bsc#1271982 * bsc#1271984 * bsc#1271986 * bsc#1271987 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2026-10723 * CVE-2026-11331 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-13204 * CVE-2026-13321 CVSS scores: * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3477=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3477=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3477=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3477=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3477=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3477=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * bind-utils-9.16.50-150500.8.41.1 * bind-debuginfo-9.16.50-150500.8.41.1 * bind-9.16.50-150500.8.41.1 * bind-utils-debuginfo-9.16.50-150500.8.41.1 * bind-debugsource-9.16.50-150500.8.41.1 * openSUSE Leap 15.5 (noarch) * python3-bind-9.16.50-150500.8.41.1 * bind-doc-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * bind-utils-9.16.50-150500.8.41.1 * bind-debuginfo-9.16.50-150500.8.41.1 * bind-9.16.50-150500.8.41.1 * bind-utils-debuginfo-9.16.50-150500.8.41.1 * bind-debugsource-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-bind-9.16.50-150500.8.41.1 * bind-doc-9.16.50-150500.8.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * bind-utils-9.16.50-150500.8.41.1 * bind-debuginfo-9.16.50-150500.8.41.1 * bind-9.16.50-150500.8.41.1 * bind-utils-debuginfo-9.16.50-150500.8.41.1 * bind-debugsource-9.16.50-150500.8.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python3-bind-9.16.50-150500.8.41.1 * bind-doc-9.16.50-150500.8.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * bind-utils-9.16.50-150500.8.41.1 * bind-debuginfo-9.16.50-150500.8.41.1 * bind-9.16.50-150500.8.41.1 * bind-utils-debuginfo-9.16.50-150500.8.41.1 * bind-debugsource-9.16.50-150500.8.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python3-bind-9.16.50-150500.8.41.1 * bind-doc-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * bind-utils-9.16.50-150500.8.41.1 * bind-9.16.50-150500.8.41.1 * bind-debuginfo-9.16.50-150500.8.41.1 * bind-utils-debuginfo-9.16.50-150500.8.41.1 * bind-debugsource-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-bind-9.16.50-150500.8.41.1 * bind-doc-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * bind-utils-9.16.50-150500.8.41.1 * bind-utils-debuginfo-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-bind-9.16.50-150500.8.41.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * bind-debugsource-9.16.50-150500.8.41.1 * bind-debuginfo-9.16.50-150500.8.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:31:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:31:55 -0000 Subject: SUSE-SU-2026:3476-1: important: Security update for bind Message-ID: <178583231514.6741.1483001546597671521@dac66d42c24b> # Security update for bind Announcement ID: SUSE-SU-2026:3476-1 Release Date: 2026-08-03T16:58:19Z Rating: important References: * bsc#1271982 * bsc#1271984 * bsc#1271986 * bsc#1271987 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2026-10723 * CVE-2026-11331 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-13204 * CVE-2026-13321 CVSS scores: * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves six vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3476=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3476=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3476=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3476=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3476=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * bind-utils-debuginfo-9.16.50-150400.5.65.1 * bind-utils-9.16.50-150400.5.65.1 * bind-debugsource-9.16.50-150400.5.65.1 * bind-debuginfo-9.16.50-150400.5.65.1 * bind-9.16.50-150400.5.65.1 * openSUSE Leap 15.4 (noarch) * python3-bind-9.16.50-150400.5.65.1 * bind-doc-9.16.50-150400.5.65.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * bind-utils-debuginfo-9.16.50-150400.5.65.1 * bind-utils-9.16.50-150400.5.65.1 * bind-debugsource-9.16.50-150400.5.65.1 * bind-debuginfo-9.16.50-150400.5.65.1 * bind-9.16.50-150400.5.65.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-bind-9.16.50-150400.5.65.1 * bind-doc-9.16.50-150400.5.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * bind-utils-debuginfo-9.16.50-150400.5.65.1 * bind-utils-9.16.50-150400.5.65.1 * bind-debugsource-9.16.50-150400.5.65.1 * bind-debuginfo-9.16.50-150400.5.65.1 * bind-9.16.50-150400.5.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-bind-9.16.50-150400.5.65.1 * bind-doc-9.16.50-150400.5.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * bind-utils-debuginfo-9.16.50-150400.5.65.1 * bind-utils-9.16.50-150400.5.65.1 * bind-debugsource-9.16.50-150400.5.65.1 * bind-debuginfo-9.16.50-150400.5.65.1 * bind-9.16.50-150400.5.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-bind-9.16.50-150400.5.65.1 * bind-doc-9.16.50-150400.5.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * bind-utils-debuginfo-9.16.50-150400.5.65.1 * bind-utils-9.16.50-150400.5.65.1 * bind-debuginfo-9.16.50-150400.5.65.1 * bind-debugsource-9.16.50-150400.5.65.1 * bind-9.16.50-150400.5.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-bind-9.16.50-150400.5.65.1 * bind-doc-9.16.50-150400.5.65.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:32:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:32:51 -0000 Subject: SUSE-SU-2026:3475-1: moderate: Security update for s390-tools Message-ID: <178583237125.6741.12975084822636192769@dac66d42c24b> # Security update for s390-tools Announcement ID: SUSE-SU-2026:3475-1 Release Date: 2026-08-03T16:46:06Z Rating: moderate References: * bsc#1270185 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for s390-tools fixes the following issue * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3475=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3475=1 ## Package List: * openSUSE Leap 15.5 (s390x) * s390-tools-hmcdrvfs-debuginfo-2.31.0-150500.9.32.1 * libekmfweb1-debuginfo-2.31.0-150500.9.32.1 * osasnmpd-2.31.0-150500.9.32.1 * libkmipclient1-devel-2.31.0-150500.9.32.1 * s390-tools-hmcdrvfs-2.31.0-150500.9.32.1 * libkmipclient1-debuginfo-2.31.0-150500.9.32.1 * libekmfweb1-2.31.0-150500.9.32.1 * osasnmpd-debuginfo-2.31.0-150500.9.32.1 * s390-tools-chreipl-fcp-mpath-2.31.0-150500.9.32.1 * libekmfweb1-devel-2.31.0-150500.9.32.1 * libkmipclient1-2.31.0-150500.9.32.1 * s390-tools-zdsfs-debuginfo-2.31.0-150500.9.32.1 * s390-tools-zdsfs-2.31.0-150500.9.32.1 * openSUSE Leap 15.5 (s390x x86_64) * s390-tools-debugsource-2.31.0-150500.9.32.1 * s390-tools-debuginfo-2.31.0-150500.9.32.1 * s390-tools-2.31.0-150500.9.32.1 * openSUSE Leap 15.5 (noarch) * s390-tools-genprotimg-data-2.31.0-150500.9.32.1 * SUSE Linux Enterprise Micro 5.5 (s390x x86_64) * s390-tools-2.31.0-150500.9.32.1 * s390-tools-debuginfo-2.31.0-150500.9.32.1 * s390-tools-debugsource-2.31.0-150500.9.32.1 * SUSE Linux Enterprise Micro 5.5 (s390x) * libekmfweb1-2.31.0-150500.9.32.1 * libkmipclient1-2.31.0-150500.9.32.1 * libekmfweb1-debuginfo-2.31.0-150500.9.32.1 * libkmipclient1-debuginfo-2.31.0-150500.9.32.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * s390-tools-genprotimg-data-2.31.0-150500.9.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270185 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:33:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:33:46 -0000 Subject: SUSE-SU-2026:3474-1: moderate: Security update for s390-tools Message-ID: <178583242698.6741.8612798481363535361@dac66d42c24b> # Security update for s390-tools Announcement ID: SUSE-SU-2026:3474-1 Release Date: 2026-08-03T16:45:58Z Rating: moderate References: * bsc#1270185 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for s390-tools fixes the following issue * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3474=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3474=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3474=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3474=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3474=1 ## Package List: * openSUSE Leap 15.4 (s390x) * s390-tools-hmcdrvfs-debuginfo-2.31.0-150400.7.34.1 * s390-tools-zdsfs-debuginfo-2.31.0-150400.7.34.1 * libekmfweb1-devel-2.31.0-150400.7.34.1 * libkmipclient1-debuginfo-2.31.0-150400.7.34.1 * libkmipclient1-devel-2.31.0-150400.7.34.1 * s390-tools-chreipl-fcp-mpath-2.31.0-150400.7.34.1 * libekmfweb1-2.31.0-150400.7.34.1 * libkmipclient1-2.31.0-150400.7.34.1 * s390-tools-hmcdrvfs-2.31.0-150400.7.34.1 * osasnmpd-2.31.0-150400.7.34.1 * libekmfweb1-debuginfo-2.31.0-150400.7.34.1 * osasnmpd-debuginfo-2.31.0-150400.7.34.1 * s390-tools-zdsfs-2.31.0-150400.7.34.1 * openSUSE Leap 15.4 (noarch) * s390-tools-genprotimg-data-2.31.0-150400.7.34.1 * openSUSE Leap 15.4 (s390x x86_64) * s390-tools-debugsource-2.31.0-150400.7.34.1 * s390-tools-debuginfo-2.31.0-150400.7.34.1 * s390-tools-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (s390x) * s390-tools-debugsource-2.31.0-150400.7.34.1 * libkmipclient1-debuginfo-2.31.0-150400.7.34.1 * s390-tools-debuginfo-2.31.0-150400.7.34.1 * libkmipclient1-2.31.0-150400.7.34.1 * libekmfweb1-2.31.0-150400.7.34.1 * s390-tools-2.31.0-150400.7.34.1 * libekmfweb1-debuginfo-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * s390-tools-genprotimg-data-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro 5.3 (s390x) * s390-tools-debugsource-2.31.0-150400.7.34.1 * libkmipclient1-debuginfo-2.31.0-150400.7.34.1 * s390-tools-debuginfo-2.31.0-150400.7.34.1 * libkmipclient1-2.31.0-150400.7.34.1 * libekmfweb1-2.31.0-150400.7.34.1 * s390-tools-2.31.0-150400.7.34.1 * libekmfweb1-debuginfo-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * s390-tools-genprotimg-data-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (s390x) * s390-tools-debugsource-2.31.0-150400.7.34.1 * libkmipclient1-debuginfo-2.31.0-150400.7.34.1 * s390-tools-debuginfo-2.31.0-150400.7.34.1 * libkmipclient1-2.31.0-150400.7.34.1 * libekmfweb1-2.31.0-150400.7.34.1 * s390-tools-2.31.0-150400.7.34.1 * libekmfweb1-debuginfo-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * s390-tools-genprotimg-data-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro 5.4 (s390x) * s390-tools-debugsource-2.31.0-150400.7.34.1 * libkmipclient1-debuginfo-2.31.0-150400.7.34.1 * s390-tools-debuginfo-2.31.0-150400.7.34.1 * libkmipclient1-2.31.0-150400.7.34.1 * libekmfweb1-2.31.0-150400.7.34.1 * s390-tools-2.31.0-150400.7.34.1 * libekmfweb1-debuginfo-2.31.0-150400.7.34.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * s390-tools-genprotimg-data-2.31.0-150400.7.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270185 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:34:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:34:42 -0000 Subject: SUSE-SU-2026:3473-1: important: Security update for aws-iam-authenticator Message-ID: <178583248259.6741.2057160359021959818@dac66d42c24b> # Security update for aws-iam-authenticator Announcement ID: SUSE-SU-2026:3473-1 Release Date: 2026-08-03T16:45:13Z Rating: important References: * bsc#1266651 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for aws-iam-authenticator fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266651). Changes for aws-iam-authenticator: * Update golang.org/x/net to v0.57.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3473=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3473=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3473=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3473=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.7.18-150000.1.20.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.7.18-150000.1.20.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.7.18-150000.1.20.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * aws-iam-authenticator-0.7.18-150000.1.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266651 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:35:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:35:21 -0000 Subject: SUSE-SU-2026:3472-1: important: Security update for google-cloud-sap-agent Message-ID: <178583252174.6741.3279592850199393605@dac66d42c24b> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:3472-1 Release Date: 2026-08-03T16:44:35Z Rating: important References: * bsc#1266604 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266604). Changes for google-cloud-sap-agent: * Update golang.org/x/net to v0.57.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3472=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3472=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3472=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3472=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.77.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.77.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.77.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.77.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266604 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:36:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:36:00 -0000 Subject: SUSE-SU-2026:3471-1: important: Security update for google-cloud-sap-agent Message-ID: <178583256050.6741.11986141594915774135@dac66d42c24b> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:3471-1 Release Date: 2026-08-03T16:44:01Z Rating: important References: * bsc#1266604 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issue: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266604). Changes for google-cloud-sap-agent: * Update golang.org/x/net to v0.57.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3471=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-6.75.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266604 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:36:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:36:40 -0000 Subject: SUSE-SU-2026:3470-1: important: Security update for spice-vdagent Message-ID: <178583260076.6741.8668759753745394811@dac66d42c24b> # Security update for spice-vdagent Announcement ID: SUSE-SU-2026:3470-1 Release Date: 2026-08-03T16:42:20Z Rating: important References: * bsc#1269553 * bsc#1269554 Cross-References: * CVE-2026-57965 * CVE-2026-57966 CVSS scores: * CVE-2026-57965 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H * CVE-2026-57965 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-57965 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-57966 ( SUSE ): 6.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H * CVE-2026-57966 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-57966 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for spice-vdagent fixes the following issues: * CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer overflow (bsc#1269553). * CVE-2026-57966: improper sanitization allows a compromised SPICE host to write arbitrary files to any location on the guest operating system (bsc#1269554). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3470=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3470=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3470=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3470=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3470=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * spice-vdagent-debugsource-0.21.0-150300.3.6.1 * spice-vdagent-debuginfo-0.21.0-150300.3.6.1 * spice-vdagent-0.21.0-150300.3.6.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * spice-vdagent-debugsource-0.21.0-150300.3.6.1 * spice-vdagent-debuginfo-0.21.0-150300.3.6.1 * spice-vdagent-0.21.0-150300.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * spice-vdagent-0.21.0-150300.3.6.1 * spice-vdagent-debuginfo-0.21.0-150300.3.6.1 * spice-vdagent-debugsource-0.21.0-150300.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * spice-vdagent-debugsource-0.21.0-150300.3.6.1 * spice-vdagent-debuginfo-0.21.0-150300.3.6.1 * spice-vdagent-0.21.0-150300.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * spice-vdagent-debugsource-0.21.0-150300.3.6.1 * spice-vdagent-debuginfo-0.21.0-150300.3.6.1 * spice-vdagent-0.21.0-150300.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57965.html * https://www.suse.com/security/cve/CVE-2026-57966.html * https://bugzilla.suse.com/show_bug.cgi?id=1269553 * https://bugzilla.suse.com/show_bug.cgi?id=1269554 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:37:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:37:36 -0000 Subject: SUSE-SU-2026:3469-1: important: Security update for nginx Message-ID: <178583265643.6741.5204205950088463124@dac66d42c24b> # Security update for nginx Announcement ID: SUSE-SU-2026:3469-1 Release Date: 2026-08-03T16:40:38Z Rating: important References: * bsc#1271514 Cross-References: * CVE-2026-42533 CVSS scores: * CVE-2026-42533 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-42533 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42533 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42533 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for nginx fixes the following issue: * CVE-2026-42533: referencing regex capture variables before map output variables can trigger a heap buffer overflow (bsc#1271514). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3469=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3469=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3469=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3469=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * nginx-debugsource-1.21.5-150600.10.27.1 * nginx-debuginfo-1.21.5-150600.10.27.1 * nginx-1.21.5-150600.10.27.1 * Server Applications Module 15-SP7 (noarch) * nginx-source-1.21.5-150600.10.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nginx-debugsource-1.21.5-150600.10.27.1 * nginx-1.21.5-150600.10.27.1 * nginx-debuginfo-1.21.5-150600.10.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nginx-source-1.21.5-150600.10.27.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nginx-debuginfo-1.21.5-150600.10.27.1 * nginx-debugsource-1.21.5-150600.10.27.1 * nginx-1.21.5-150600.10.27.1 * openSUSE Leap 15.6 (noarch) * nginx-source-1.21.5-150600.10.27.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nginx-debuginfo-1.21.5-150600.10.27.1 * nginx-debugsource-1.21.5-150600.10.27.1 * nginx-1.21.5-150600.10.27.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nginx-source-1.21.5-150600.10.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42533.html * https://bugzilla.suse.com/show_bug.cgi?id=1271514 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 08:38:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 08:38:31 -0000 Subject: SUSE-SU-2026:3468-1: important: Security update for rrdtool Message-ID: <178583271194.6741.5721436105483994524@dac66d42c24b> # Security update for rrdtool Announcement ID: SUSE-SU-2026:3468-1 Release Date: 2026-08-03T16:34:53Z Rating: important References: * bsc#1267243 Cross-References: * CVE-2026-43958 CVSS scores: * CVE-2026-43958 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43958 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43958 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for rrdtool fixes the following issue: * CVE-2026-43958: stack buffer overflow in `rrdcached` `handle_request_create()` can lead to local privilege escalation via unbounded DS/RRA arguments (bsc#1267243). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3468=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3468=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3468=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3468=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-rrdtool-1.8.0-150600.3.9.1 * rrdtool-debugsource-1.8.0-150600.3.9.1 * rrdtool-1.8.0-150600.3.9.1 * librrd8-1.8.0-150600.3.9.1 * librrd8-debuginfo-1.8.0-150600.3.9.1 * rrdtool-debuginfo-1.8.0-150600.3.9.1 * rrdtool-devel-1.8.0-150600.3.9.1 * perl-rrdtool-debuginfo-1.8.0-150600.3.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-rrdtool-1.8.0-150600.3.9.1 * rrdtool-debugsource-1.8.0-150600.3.9.1 * rrdtool-1.8.0-150600.3.9.1 * librrd8-1.8.0-150600.3.9.1 * librrd8-debuginfo-1.8.0-150600.3.9.1 * rrdtool-debuginfo-1.8.0-150600.3.9.1 * rrdtool-devel-1.8.0-150600.3.9.1 * perl-rrdtool-debuginfo-1.8.0-150600.3.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * perl-rrdtool-1.8.0-150600.3.9.1 * librrd8-debuginfo-1.8.0-150600.3.9.1 * tcl-rrdtool-debuginfo-1.8.0-150600.3.9.1 * tcl-rrdtool-1.8.0-150600.3.9.1 * lua-rrdtool-1.8.0-150600.3.9.1 * rrdtool-1.8.0-150600.3.9.1 * rrdtool-debuginfo-1.8.0-150600.3.9.1 * ruby-rrdtool-debuginfo-1.8.0-150600.3.9.1 * python3-rrdtool-1.8.0-150600.3.9.1 * python3-rrdtool-debuginfo-1.8.0-150600.3.9.1 * rrdtool-cached-debuginfo-1.8.0-150600.3.9.1 * rrdtool-cached-1.8.0-150600.3.9.1 * ruby-rrdtool-1.8.0-150600.3.9.1 * rrdtool-devel-1.8.0-150600.3.9.1 * rrdtool-debugsource-1.8.0-150600.3.9.1 * librrd8-1.8.0-150600.3.9.1 * rrdtool-doc-1.8.0-150600.3.9.1 * lua-rrdtool-debuginfo-1.8.0-150600.3.9.1 * perl-rrdtool-debuginfo-1.8.0-150600.3.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-rrdtool-1.8.0-150600.3.9.1 * rrdtool-debugsource-1.8.0-150600.3.9.1 * rrdtool-1.8.0-150600.3.9.1 * librrd8-1.8.0-150600.3.9.1 * librrd8-debuginfo-1.8.0-150600.3.9.1 * rrdtool-debuginfo-1.8.0-150600.3.9.1 * rrdtool-devel-1.8.0-150600.3.9.1 * perl-rrdtool-debuginfo-1.8.0-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43958.html * https://bugzilla.suse.com/show_bug.cgi?id=1267243 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:30:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:30:30 -0000 Subject: SUSE-SU-2026:3493-1: important: Security update for libpng16 Message-ID: <178586103014.286.16115795698132697668@438c6482d549> # Security update for libpng16 Announcement ID: SUSE-SU-2026:3493-1 Release Date: 2026-08-04T12:11:14Z Rating: important References: * jsc#PED-16190 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that contains one feature can now be installed. ## Description: This update for libpng16 fixes the following issues: Changes for libpng16: * version update to 1.6.58 (jsc#PED-16190). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3493=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3493=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3493=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3493=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le s390x x86_64) * libpng16-16-1.6.58-150600.3.23.1 * libpng16-16-debuginfo-1.6.58-150600.3.23.1 * libpng16-debugsource-1.6.58-150600.3.23.1 * libpng16-devel-1.6.58-150600.3.23.1 * libpng16-compat-devel-1.6.58-150600.3.23.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libpng16-16-32bit-1.6.58-150600.3.23.1 * libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libpng16-16-1.6.58-150600.3.23.1 * libpng16-16-debuginfo-1.6.58-150600.3.23.1 * libpng16-debugsource-1.6.58-150600.3.23.1 * libpng16-devel-1.6.58-150600.3.23.1 * libpng16-compat-devel-1.6.58-150600.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libpng16-16-32bit-1.6.58-150600.3.23.1 * libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1 * openSUSE Leap 15.6 (x86_64) * libpng16-16-32bit-1.6.58-150600.3.23.1 * libpng16-compat-devel-32bit-1.6.58-150600.3.23.1 * libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1 * libpng16-devel-32bit-1.6.58-150600.3.23.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libpng16-16-1.6.58-150600.3.23.1 * libpng16-compat-devel-1.6.58-150600.3.23.1 * libpng16-16-debuginfo-1.6.58-150600.3.23.1 * libpng16-debugsource-1.6.58-150600.3.23.1 * libpng16-tools-1.6.58-150600.3.23.1 * libpng16-devel-1.6.58-150600.3.23.1 * libpng16-tools-debuginfo-1.6.58-150600.3.23.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpng16-devel-64bit-1.6.58-150600.3.23.1 * libpng16-16-64bit-debuginfo-1.6.58-150600.3.23.1 * libpng16-compat-devel-64bit-1.6.58-150600.3.23.1 * libpng16-16-64bit-1.6.58-150600.3.23.1 * Basesystem Module 15-SP7 (ppc64le s390x x86_64) * libpng16-16-1.6.58-150600.3.23.1 * libpng16-16-debuginfo-1.6.58-150600.3.23.1 * libpng16-debugsource-1.6.58-150600.3.23.1 * libpng16-devel-1.6.58-150600.3.23.1 * libpng16-compat-devel-1.6.58-150600.3.23.1 * Basesystem Module 15-SP7 (x86_64) * libpng16-16-32bit-1.6.58-150600.3.23.1 * libpng16-16-32bit-debuginfo-1.6.58-150600.3.23.1 ## References: * https://jira.suse.com/browse/PED-16190 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:31:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:31:29 -0000 Subject: SUSE-SU-2026:3492-1: moderate: Security update for alsa Message-ID: <178586108999.286.4429406956408726368@438c6482d549> # Security update for alsa Announcement ID: SUSE-SU-2026:3492-1 Release Date: 2026-08-04T11:58:57Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that can allow attackers to corrupt memory (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3492=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3492=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * alsa-debugsource-1.2.8-150500.3.3.1 * libasound2-1.2.8-150500.3.3.1 * libasound2-debuginfo-1.2.8-150500.3.3.1 * alsa-devel-1.2.8-150500.3.3.1 * alsa-1.2.8-150500.3.3.1 * openSUSE Leap 15.5 (x86_64) * libatopology2-32bit-1.2.8-150500.3.3.1 * alsa-topology-devel-32bit-1.2.8-150500.3.3.1 * libasound2-32bit-1.2.8-150500.3.3.1 * libatopology2-32bit-debuginfo-1.2.8-150500.3.3.1 * libasound2-32bit-debuginfo-1.2.8-150500.3.3.1 * alsa-devel-32bit-1.2.8-150500.3.3.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le x86_64) * libatopology2-debuginfo-1.2.8-150500.3.3.1 * libatopology2-1.2.8-150500.3.3.1 * alsa-topology-devel-1.2.8-150500.3.3.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libasound2-64bit-debuginfo-1.2.8-150500.3.3.1 * libasound2-64bit-1.2.8-150500.3.3.1 * libatopology2-64bit-1.2.8-150500.3.3.1 * alsa-topology-devel-64bit-1.2.8-150500.3.3.1 * alsa-devel-64bit-1.2.8-150500.3.3.1 * libatopology2-64bit-debuginfo-1.2.8-150500.3.3.1 * openSUSE Leap 15.5 (noarch) * alsa-docs-1.2.8-150500.3.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libasound2-1.2.8-150500.3.3.1 * alsa-debugsource-1.2.8-150500.3.3.1 * libasound2-debuginfo-1.2.8-150500.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:32:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:32:29 -0000 Subject: SUSE-SU-2026:3491-1: moderate: Security update for libgcrypt Message-ID: <178586114947.286.11109958727067935937@438c6482d549> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:3491-1 Release Date: 2026-08-04T11:58:46Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41989: heap-based buffer overflow when processing crafted ECDH ciphertext can lead to a denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3491=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3491=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libgcrypt-debugsource-1.9.4-150500.12.6.1 * libgcrypt20-1.9.4-150500.12.6.1 * libgcrypt-cavs-1.9.4-150500.12.6.1 * libgcrypt-devel-1.9.4-150500.12.6.1 * libgcrypt20-debuginfo-1.9.4-150500.12.6.1 * libgcrypt-devel-debuginfo-1.9.4-150500.12.6.1 * libgcrypt-cavs-debuginfo-1.9.4-150500.12.6.1 * libgcrypt20-hmac-1.9.4-150500.12.6.1 * openSUSE Leap 15.5 (x86_64) * libgcrypt20-32bit-debuginfo-1.9.4-150500.12.6.1 * libgcrypt20-32bit-1.9.4-150500.12.6.1 * libgcrypt-devel-32bit-1.9.4-150500.12.6.1 * libgcrypt20-hmac-32bit-1.9.4-150500.12.6.1 * libgcrypt-devel-32bit-debuginfo-1.9.4-150500.12.6.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libgcrypt20-hmac-64bit-1.9.4-150500.12.6.1 * libgcrypt20-64bit-debuginfo-1.9.4-150500.12.6.1 * libgcrypt-devel-64bit-1.9.4-150500.12.6.1 * libgcrypt20-64bit-1.9.4-150500.12.6.1 * libgcrypt-devel-64bit-debuginfo-1.9.4-150500.12.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libgcrypt-debugsource-1.9.4-150500.12.6.1 * libgcrypt20-debuginfo-1.9.4-150500.12.6.1 * libgcrypt20-1.9.4-150500.12.6.1 * libgcrypt20-hmac-1.9.4-150500.12.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:33:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:33:26 -0000 Subject: SUSE-SU-2026:3490-1: low: Security update for wpa_supplicant Message-ID: <178586120666.286.16370654643028073429@438c6482d549> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3490-1 Release Date: 2026-08-04T11:58:39Z Rating: low References: * bsc#1239461 Cross-References: * CVE-2025-24912 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for wpa_supplicant fixes the following issues: * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ * Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3490=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3490=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * wpa_supplicant-debugsource-2.10-150500.3.6.1 * wpa_supplicant-gui-debuginfo-2.10-150500.3.6.1 * wpa_supplicant-debuginfo-2.10-150500.3.6.1 * wpa_supplicant-gui-2.10-150500.3.6.1 * wpa_supplicant-2.10-150500.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * wpa_supplicant-debuginfo-2.10-150500.3.6.1 * wpa_supplicant-debugsource-2.10-150500.3.6.1 * wpa_supplicant-2.10-150500.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:34:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:34:23 -0000 Subject: SUSE-SU-2026:3489-1: moderate: Security update for multipath-tools Message-ID: <178586126379.286.9122033899362793835@438c6482d549> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:3489-1 Release Date: 2026-08-04T11:57:10Z Rating: moderate References: * bsc#1268144 * bsc#1268145 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that has two security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: Update to version 0.9.4+134+suse.c82f347. * kpartx: integer overflow in the GPT partition table size calculation can lead to heap OOB read via crafted USB device or disk image (bsc#1268145). * kpartx: missing bounds check can lead to a DASD VOL1 unbounded array write via a crafted DASD disk with more than 256 consecutive format labels (bsc#1268144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3489=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3489=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libmpath0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * multipath-tools-debugsource-0.9.4+134+suse.c82f347-150500.3.12.1 * multipath-tools-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1 * kpartx-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1 * libdmmp0_2_0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * libdmmp0_2_0-0.9.4+134+suse.c82f347-150500.3.12.1 * multipath-tools-devel-0.9.4+134+suse.c82f347-150500.3.12.1 * libdmmp-devel-0.9.4+134+suse.c82f347-150500.3.12.1 * kpartx-0.9.4+134+suse.c82f347-150500.3.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * multipath-tools-debugsource-0.9.4+134+suse.c82f347-150500.3.12.1 * libmpath0-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * multipath-tools-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * libmpath0-0.9.4+134+suse.c82f347-150500.3.12.1 * kpartx-debuginfo-0.9.4+134+suse.c82f347-150500.3.12.1 * multipath-tools-0.9.4+134+suse.c82f347-150500.3.12.1 * kpartx-0.9.4+134+suse.c82f347-150500.3.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268144 * https://bugzilla.suse.com/show_bug.cgi?id=1268145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:35:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:35:19 -0000 Subject: SUSE-SU-2026:3488-1: important: Security update for openssl-1_1 Message-ID: <178586131941.286.17198678120849323506@438c6482d549> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:3488-1 Release Date: 2026-08-04T11:55:49Z Rating: important References: * bsc#1271712 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issue * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3488=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3488=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3488=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3488=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3488=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3488=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1l-150500.17.60.1 * openssl-1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-1.1.1l-150500.17.60.1 * openssl-1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * openssl-1_1-debugsource-1.1.1l-150500.17.60.1 * openssl-1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-1.1.1l-150500.17.60.1 * openssl-1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libopenssl1_1-32bit-1.1.1l-150500.17.60.1 * libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1l-150500.17.60.1 * openssl-1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-1.1.1l-150500.17.60.1 * openssl-1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-1.1.1l-150500.17.60.1 * openSUSE Leap 15.5 (x86_64) * libopenssl1_1-32bit-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-32bit-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1 * libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libopenssl1_1-64bit-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-64bit-1.1.1l-150500.17.60.1 * libopenssl1_1-64bit-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-64bit-1.1.1l-150500.17.60.1 * openSUSE Leap 15.5 (noarch) * openssl-1_1-doc-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * openssl-1_1-debugsource-1.1.1l-150500.17.60.1 * openssl-1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-1.1.1l-150500.17.60.1 * openssl-1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libopenssl1_1-32bit-1.1.1l-150500.17.60.1 * libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1l-150500.17.60.1 * openssl-1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-1.1.1l-150500.17.60.1 * openssl-1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libopenssl1_1-32bit-1.1.1l-150500.17.60.1 * libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * openssl-1_1-debugsource-1.1.1l-150500.17.60.1 * openssl-1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-debuginfo-1.1.1l-150500.17.60.1 * libopenssl-1_1-devel-1.1.1l-150500.17.60.1 * openssl-1_1-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-1.1.1l-150500.17.60.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libopenssl1_1-32bit-1.1.1l-150500.17.60.1 * libopenssl1_1-32bit-debuginfo-1.1.1l-150500.17.60.1 * libopenssl1_1-hmac-32bit-1.1.1l-150500.17.60.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:36:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:36:15 -0000 Subject: SUSE-SU-2026:3487-1: important: Security update for openssl-1_1 Message-ID: <178586137563.286.13750411791658469904@438c6482d549> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:3487-1 Release Date: 2026-08-04T11:55:16Z Rating: important References: * bsc#1271712 Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issue * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3487=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3487=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl1_1-1.1.1d-2.134.2 * libopenssl-1_1-devel-1.1.1d-2.134.2 * libopenssl1_1-hmac-1.1.1d-2.134.2 * libopenssl1_1-debuginfo-1.1.1d-2.134.2 * openssl-1_1-debuginfo-1.1.1d-2.134.2 * openssl-1_1-1.1.1d-2.134.2 * openssl-1_1-debugsource-1.1.1d-2.134.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libopenssl1_1-32bit-1.1.1d-2.134.2 * libopenssl1_1-debuginfo-32bit-1.1.1d-2.134.2 * libopenssl-1_1-devel-32bit-1.1.1d-2.134.2 * libopenssl1_1-hmac-32bit-1.1.1d-2.134.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libopenssl1_1-1.1.1d-2.134.2 * libopenssl-1_1-devel-1.1.1d-2.134.2 * libopenssl-1_1-devel-32bit-1.1.1d-2.134.2 * libopenssl1_1-hmac-1.1.1d-2.134.2 * libopenssl1_1-32bit-1.1.1d-2.134.2 * libopenssl1_1-debuginfo-1.1.1d-2.134.2 * openssl-1_1-debuginfo-1.1.1d-2.134.2 * openssl-1_1-1.1.1d-2.134.2 * libopenssl1_1-debuginfo-32bit-1.1.1d-2.134.2 * openssl-1_1-debugsource-1.1.1d-2.134.2 * libopenssl1_1-hmac-32bit-1.1.1d-2.134.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:36:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:36:55 -0000 Subject: SUSE-SU-2026:3486-1: moderate: Security update for openssl-3 Message-ID: <178586141523.286.13006087215179763484@438c6482d549> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3486-1 Release Date: 2026-08-04T11:54:54Z Rating: moderate References: * bsc#1271712 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that has one security fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3486=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3486=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3486=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3486=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3486=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3486=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3486=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3486=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3486=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * openssl-3-3.0.8-150400.4.93.1 * openssl-3-debuginfo-3.0.8-150400.4.93.1 * libopenssl-3-devel-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * openssl-3-3.0.8-150400.4.93.1 * openssl-3-debuginfo-3.0.8-150400.4.93.1 * libopenssl-3-devel-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * openSUSE Leap 15.4 (noarch) * openssl-3-doc-3.0.8-150400.4.93.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libopenssl3-64bit-debuginfo-3.0.8-150400.4.93.1 * libopenssl3-64bit-3.0.8-150400.4.93.1 * libopenssl-3-devel-64bit-3.0.8-150400.4.93.1 * openSUSE Leap 15.4 (x86_64) * libopenssl-3-devel-32bit-3.0.8-150400.4.93.1 * libopenssl3-32bit-3.0.8-150400.4.93.1 * libopenssl3-32bit-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * openssl-3-3.0.8-150400.4.93.1 * openssl-3-debuginfo-3.0.8-150400.4.93.1 * libopenssl-3-devel-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * openssl-3-3.0.8-150400.4.93.1 * openssl-3-debuginfo-3.0.8-150400.4.93.1 * libopenssl-3-devel-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl3-3.0.8-150400.4.93.1 * openssl-3-debugsource-3.0.8-150400.4.93.1 * openssl-3-3.0.8-150400.4.93.1 * openssl-3-debuginfo-3.0.8-150400.4.93.1 * libopenssl-3-devel-3.0.8-150400.4.93.1 * libopenssl3-debuginfo-3.0.8-150400.4.93.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:37:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:37:52 -0000 Subject: SUSE-SU-2026:3485-1: important: Security update for spice-vdagent Message-ID: <178586147270.286.11950337995550705865@438c6482d549> # Security update for spice-vdagent Announcement ID: SUSE-SU-2026:3485-1 Release Date: 2026-08-04T11:53:55Z Rating: important References: * bsc#1269553 * bsc#1269554 Cross-References: * CVE-2026-57965 * CVE-2026-57966 CVSS scores: * CVE-2026-57965 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H * CVE-2026-57965 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-57965 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-57966 ( SUSE ): 6.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H * CVE-2026-57966 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-57966 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for spice-vdagent fixes the following issues: * CVE-2026-57965: integer overflow in `udscs_write()` can lead to heap buffer overflow (bsc#1269553). * CVE-2026-57966: improper sanitization allows a compromised SPICE host to write arbitrary files to any location on the guest operating system (bsc#1269554). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3485=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3485=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3485=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3485=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3485=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3485=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3485=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3485=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * spice-vdagent-debugsource-0.22.1-150500.4.3.1 * spice-vdagent-debuginfo-0.22.1-150500.4.3.1 * spice-vdagent-0.22.1-150500.4.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57965.html * https://www.suse.com/security/cve/CVE-2026-57966.html * https://bugzilla.suse.com/show_bug.cgi?id=1269553 * https://bugzilla.suse.com/show_bug.cgi?id=1269554 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:38:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:38:56 -0000 Subject: SUSE-SU-2026:3484-1: important: Security update for bind Message-ID: <178586153650.286.16801708842165232591@438c6482d549> # Security update for bind Announcement ID: SUSE-SU-2026:3484-1 Release Date: 2026-08-04T11:52:47Z Rating: important References: * bsc#1271986 * bsc#1271987 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-13204 * CVE-2026-13321 CVSS scores: * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues * CVE-2026-11622: Potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field (bsc#1271990). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3484=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3484=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * bind-devel-9.11.22-3.74.1 * libisc1107-debuginfo-9.11.22-3.74.1 * libisccc161-9.11.22-3.74.1 * bind-utils-9.11.22-3.74.1 * libdns1110-9.11.22-3.74.1 * libbind9-161-9.11.22-3.74.1 * liblwres161-9.11.22-3.74.1 * libisccfg163-9.11.22-3.74.1 * bind-debuginfo-9.11.22-3.74.1 * libisccfg163-debuginfo-9.11.22-3.74.1 * libisc1107-9.11.22-3.74.1 * libbind9-161-debuginfo-9.11.22-3.74.1 * bind-9.11.22-3.74.1 * bind-chrootenv-9.11.22-3.74.1 * libisccc161-debuginfo-9.11.22-3.74.1 * libirs161-debuginfo-9.11.22-3.74.1 * libirs161-9.11.22-3.74.1 * liblwres161-debuginfo-9.11.22-3.74.1 * libdns1110-debuginfo-9.11.22-3.74.1 * bind-debugsource-9.11.22-3.74.1 * bind-utils-debuginfo-9.11.22-3.74.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * python-bind-9.11.22-3.74.1 * bind-doc-9.11.22-3.74.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libisc1107-32bit-9.11.22-3.74.1 * libisc1107-debuginfo-32bit-9.11.22-3.74.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * bind-devel-9.11.22-3.74.1 * libisc1107-debuginfo-9.11.22-3.74.1 * libisccc161-9.11.22-3.74.1 * bind-utils-9.11.22-3.74.1 * libisc1107-32bit-9.11.22-3.74.1 * libdns1110-9.11.22-3.74.1 * libbind9-161-9.11.22-3.74.1 * liblwres161-9.11.22-3.74.1 * libisccfg163-9.11.22-3.74.1 * bind-debuginfo-9.11.22-3.74.1 * libisccfg163-debuginfo-9.11.22-3.74.1 * libisc1107-9.11.22-3.74.1 * libbind9-161-debuginfo-9.11.22-3.74.1 * bind-9.11.22-3.74.1 * bind-chrootenv-9.11.22-3.74.1 * libisc1107-debuginfo-32bit-9.11.22-3.74.1 * libisccc161-debuginfo-9.11.22-3.74.1 * libirs161-9.11.22-3.74.1 * libirs161-debuginfo-9.11.22-3.74.1 * liblwres161-debuginfo-9.11.22-3.74.1 * libdns1110-debuginfo-9.11.22-3.74.1 * bind-debugsource-9.11.22-3.74.1 * bind-utils-debuginfo-9.11.22-3.74.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python-bind-9.11.22-3.74.1 * bind-doc-9.11.22-3.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:39:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:39:36 -0000 Subject: SUSE-SU-2026:3483-1: important: Security update for valkey Message-ID: <178586157684.286.6709599459201130360@438c6482d549> # Security update for valkey Announcement ID: SUSE-SU-2026:3483-1 Release Date: 2026-08-04T11:46:57Z Rating: important References: * bsc#1272442 * bsc#1272443 Cross-References: * CVE-2026-56684 * CVE-2026-63639 CVSS scores: * CVE-2026-56684 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63639 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for valkey fixes the following issues * CVE-2026-56684: use-after-free in TLS connection handling (bsc#1272443). * CVE-2026-63639: RCE via corrupt stream RDB files containing a shared NACK across consumers (bsc#1272442). Changes for valkey: * Update to 8.0.10. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3483=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3483=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3483=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * valkey-debugsource-8.0.10-150600.13.28.1 * valkey-devel-8.0.10-150600.13.28.1 * valkey-debuginfo-8.0.10-150600.13.28.1 * valkey-8.0.10-150600.13.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * valkey-compat-redis-8.0.10-150600.13.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * valkey-devel-8.0.10-150600.13.28.1 * valkey-debuginfo-8.0.10-150600.13.28.1 * valkey-8.0.10-150600.13.28.1 * valkey-debugsource-8.0.10-150600.13.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * valkey-compat-redis-8.0.10-150600.13.28.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * valkey-devel-8.0.10-150600.13.28.1 * valkey-debuginfo-8.0.10-150600.13.28.1 * valkey-8.0.10-150600.13.28.1 * valkey-debugsource-8.0.10-150600.13.28.1 * openSUSE Leap 15.6 (noarch) * valkey-compat-redis-8.0.10-150600.13.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56684.html * https://www.suse.com/security/cve/CVE-2026-63639.html * https://bugzilla.suse.com/show_bug.cgi?id=1272442 * https://bugzilla.suse.com/show_bug.cgi?id=1272443 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:41:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:41:00 -0000 Subject: SUSE-SU-2026:3482-1: important: Security update for netty, netty-tcnative Message-ID: <178586166002.286.15860428483105004641@438c6482d549> # Security update for netty, netty-tcnative Announcement ID: SUSE-SU-2026:3482-1 Release Date: 2026-08-04T11:46:43Z Rating: important References: * bsc#1271435 * bsc#1271960 * bsc#1271961 * bsc#1272253 * bsc#1272254 * bsc#1272255 * bsc#1272257 * bsc#1272258 * bsc#1272259 * bsc#1272299 * bsc#1272300 * bsc#1272301 * bsc#1272302 * bsc#1272303 * bsc#1272304 * bsc#1272305 * bsc#1272306 * bsc#1272307 * bsc#1272518 * bsc#1272519 * bsc#1272603 Cross-References: * CVE-2026-44891 * CVE-2026-55831 * CVE-2026-55833 * CVE-2026-55851 * CVE-2026-56745 * CVE-2026-56746 * CVE-2026-56817 * CVE-2026-56818 * CVE-2026-56819 * CVE-2026-56820 * CVE-2026-56821 * CVE-2026-56822 * CVE-2026-59898 * CVE-2026-59899 * CVE-2026-59900 * CVE-2026-59901 * CVE-2026-59919 * CVE-2026-59920 * CVE-2026-59921 CVSS scores: * CVE-2026-44891 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44891 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44891 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55831 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55831 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55831 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55833 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55833 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55833 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55851 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55851 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55851 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55851 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56745 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56745 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56745 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56745 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56746 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56746 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56746 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56817 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56817 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-56817 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56817 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56819 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56819 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56819 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56820 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56820 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56820 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56820 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56821 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56821 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56822 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56822 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56822 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-59898 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-59898 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-59898 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59899 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59899 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59899 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59900 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-59900 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-59900 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59901 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59901 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59901 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59919 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59919 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59919 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59920 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59920 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59920 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59921 ( SUSE ): 6.9 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-59921 ( SUSE ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-59921 ( NVD ): 5.7 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 19 vulnerabilities and has two security fixes can now be installed. ## Description: This update for netty, netty-tcnative fixes the following issues: Upgrade netty to upstream version 4.1.136 and netty-tcnative to version 2.0.80 Final. Security issues fixed * CVE-2026-44891: memory exhaustion in `io.netty:netty-codec-stomp` (bsc#1271435). * CVE-2026-55831: resource exhaustion/DoS in `io.netty:netty-codec-http` (bsc#1271960). * CVE-2026-55833: zip bomb in `io.netty:netty-codec-http` (bsc#1271961). * CVE-2026-55851: memory exhaustion in `io.netty:netty-codec-haproxy` (bsc#1272253). * CVE-2026-56745: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272254). * CVE-2026-56746: improper access control in `io.netty:netty-codec-http` (CORS) (bsc#1272255). * CVE-2026-56817: insecure defaults in XML parsing in `io.netty:netty-codec- xml` (bsc#1272257). * CVE-2026-56818: memory leak in `io.netty:netty-codec-redis` (bsc#1272603). * CVE-2026-56819: memory leak in `io.netty:netty-codec-http2` (bsc#1272258). * CVE-2026-56820: improper certificate validation in `io.netty:netty-handler- ssl-ocsp` (bsc#1272259). * CVE-2026-56821: improper certificate revocation check in `io.netty:netty- handler-ssl-ocsp` (bsc#1272299). * CVE-2026-56822: time-of-check/time-of-use in `io.netty:netty-handler-ssl- ocsp` (bsc#1272300). * CVE-2026-59898: protocol version confusion in `io.netty:netty-codec-http` (websocket) (bsc#1272302). * CVE-2026-59899: memory exhaustion in `io.netty:netty-codec-http` (bsc#1272301). * CVE-2026-59900: improper header neutralization in `io.netty:netty-codec- http2` (bsc#1272303). * CVE-2026-59901: infinite loop in `io.netty:netty-codec-compression` (bzip2) (bsc#1272304). * CVE-2026-59919: improper CR/LF neutralization in `io.netty:netty-codec- haproxy` (bsc#1272305). * CVE-2026-59920: improper CR/LF neutrolization in `io.netty:netty-codec- stomp` (bsc#1272306). * CVE-2026-59921: improper CR/LF neutralization in `io.netty:netty-codec-http` (multipart) (bsc#1272307). * Memory leak in `io.netty:netty-codec-dns` (bsc#1272519). * Uncontrolled resource consumption in `io.netty:netty-codec-xml` (bsc#1272518). Other updates and bugfixes: * Upgrade to upstream version 4.1.136: * SingleThreadEventExecutor: document Throwable safety contract on run() * Make HTTP/2 frame hashCode consistent with equals * Add BlockHound exception for DnsQueryIdSpace (#16896) * FlowControlHandler: Fix autoRead behavior * Fix incorrect bounds in error message of HpackDecoder.setMaxHeaderListSize * MQTT: Fix MQTT decoder size check after variable header replay * MQTT: Make the decodeProperties early-REPLAY check actually fire * Reject control characters at the boundary of HTTP method names (#16723) * Update to latest tcnative release * Fix HTTP 2 PUSH_PROMISE stream association validation * Fix GZIP FEXTRA extra-field handling in JdkZlibDecoder * Add opt-in validation of mandatory pseudo-header fields for HTTP/2 * Strictly validate MQTT UTF-8 Encoded String (#16939) * Stop DateFormatter trailing token from running past the parse end * IpFilter: Deprecate constructor which use accept by default * Add RFC 10008 QUERY Method support (#16966) * Correctly release and fail queued traffic-shaping writes on close (#16959) * FlowControlHandler: respect auto-read when toggled while dequeueing * IdleStateHandler: reset firstWriter/ReaderIdleEvent in resetWriteTimeout/resetReadTimeout (#16982) * Fix typo in AbstractSniHandler Javadoc * Reconcile AbstractCoalescingBufferQueue readableBytes when it drains, and fail stuck HTTP/2 streams instead of spinning empty DATA frames * Reject control characters at the boundary of the HTTP version token (#16971) * Reset UTF-8 decode state on CR in StompSubframeDecoder * HTTP2: Pass the correct number of arguments when logging goaway * FastLz: Guard decompression against truncated input (#17000) * Fix propagation of startTls for client SslContext handler * Reject non-token characters in HTTP/2 header names * Update lz4-java to 1.11.1 * Pin github actions to reduce risk (#17043) * Merge branches from forks (#17063) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3482=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3482=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3482=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3482=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3482=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3482=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3482=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3482=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3482=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3482=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3482=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3482=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-4.1.136-150200.4.53.1 * SUSE Package Hub 15 15-SP7 (noarch) * netty-javadoc-4.1.136-150200.4.53.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-tcnative-debugsource-2.0.80-150200.3.48.1 * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * netty-tcnative-2.0.80-150200.3.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * netty-tcnative-2.0.80-150200.3.48.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44891.html * https://www.suse.com/security/cve/CVE-2026-55831.html * https://www.suse.com/security/cve/CVE-2026-55833.html * https://www.suse.com/security/cve/CVE-2026-55851.html * https://www.suse.com/security/cve/CVE-2026-56745.html * https://www.suse.com/security/cve/CVE-2026-56746.html * https://www.suse.com/security/cve/CVE-2026-56817.html * https://www.suse.com/security/cve/CVE-2026-56818.html * https://www.suse.com/security/cve/CVE-2026-56819.html * https://www.suse.com/security/cve/CVE-2026-56820.html * https://www.suse.com/security/cve/CVE-2026-56821.html * https://www.suse.com/security/cve/CVE-2026-56822.html * https://www.suse.com/security/cve/CVE-2026-59898.html * https://www.suse.com/security/cve/CVE-2026-59899.html * https://www.suse.com/security/cve/CVE-2026-59900.html * https://www.suse.com/security/cve/CVE-2026-59901.html * https://www.suse.com/security/cve/CVE-2026-59919.html * https://www.suse.com/security/cve/CVE-2026-59920.html * https://www.suse.com/security/cve/CVE-2026-59921.html * https://bugzilla.suse.com/show_bug.cgi?id=1271435 * https://bugzilla.suse.com/show_bug.cgi?id=1271960 * https://bugzilla.suse.com/show_bug.cgi?id=1271961 * https://bugzilla.suse.com/show_bug.cgi?id=1272253 * https://bugzilla.suse.com/show_bug.cgi?id=1272254 * https://bugzilla.suse.com/show_bug.cgi?id=1272255 * https://bugzilla.suse.com/show_bug.cgi?id=1272257 * https://bugzilla.suse.com/show_bug.cgi?id=1272258 * https://bugzilla.suse.com/show_bug.cgi?id=1272259 * https://bugzilla.suse.com/show_bug.cgi?id=1272299 * https://bugzilla.suse.com/show_bug.cgi?id=1272300 * https://bugzilla.suse.com/show_bug.cgi?id=1272301 * https://bugzilla.suse.com/show_bug.cgi?id=1272302 * https://bugzilla.suse.com/show_bug.cgi?id=1272303 * https://bugzilla.suse.com/show_bug.cgi?id=1272304 * https://bugzilla.suse.com/show_bug.cgi?id=1272305 * https://bugzilla.suse.com/show_bug.cgi?id=1272306 * https://bugzilla.suse.com/show_bug.cgi?id=1272307 * https://bugzilla.suse.com/show_bug.cgi?id=1272518 * https://bugzilla.suse.com/show_bug.cgi?id=1272519 * https://bugzilla.suse.com/show_bug.cgi?id=1272603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:42:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:42:25 -0000 Subject: SUSE-SU-2026:3480-1: important: Security update for kubevirt Message-ID: <178586174529.286.2470261146955058889@438c6482d549> # Security update for kubevirt Announcement ID: SUSE-SU-2026:3480-1 Release Date: 2026-08-04T11:42:33Z Rating: important References: * bsc#1266575 * bsc#1269093 * bsc#1271661 * bsc#1272415 Cross-References: * CVE-2026-13201 * CVE-2026-39821 * CVE-2026-46600 * CVE-2026-56852 CVSS scores: * CVE-2026-13201 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-13201 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-46600 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46600 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for kubevirt fixes the following issues: * Security update correcting a CVE over-claim from the previous update, verified by auditing the fix code actually present in the vendored tree: * CVE-2026-39821 (bsc#1266575): the previous entry claimed this fixed by the golang.org/x/net v0.55.0 re-vendor, but 0.55.0's idna fix is compile-time gated on Unicode 16 tables, which only exist for go1.27+ - it is inert in our go1.25 builds, so the claim was incorrect. Re-vendor golang.org/x/net v0.55.0 -> v0.57.0, whose idna package rejects all-ASCII Punycode labels unconditionally; the CVE is now actually fixed. * Re-vendor golang.org/x/text v0.37.0 -> v0.40.0: CVE-2026-56852 (bsc#1271661), infinite loop on invalid input in unicode/norm. * golang.org/x/crypto v0.52.0 -> v0.54.0 (pulled in by x/net 0.57.0; no additional CVE claims, all previously listed x/crypto fixes remain included). * CVE-2026-13201 (bsc#1269093), safepath resolves a path whose last component is a symlink without detecting it, allowing metadata operations via /proc/self/fd to act on the symlink target. Backports of upstream release-1.7 commits 9ecda4ad5e and 1494cee849. * x/net 0.57.0 also contains the fix for CVE-2026-46600 (bsc#1272415) in dns/dnsmessage; kubevirt does not vendor that package (not affected), the bump merely rides past it. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3480=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-virtctl-1.7.4-150700.3.33.1 * kubevirt-virtctl-debuginfo-1.7.4-150700.3.33.1 * kubevirt-manifests-1.7.4-150700.3.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13201.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-46600.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266575 * https://bugzilla.suse.com/show_bug.cgi?id=1269093 * https://bugzilla.suse.com/show_bug.cgi?id=1271661 * https://bugzilla.suse.com/show_bug.cgi?id=1272415 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Aug 4 16:43:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 04 Aug 2026 16:43:06 -0000 Subject: SUSE-SU-2026:3478-1: important: Security update for rsyslog Message-ID: <178586178685.286.10703654002222903402@438c6482d549> # Security update for rsyslog Announcement ID: SUSE-SU-2026:3478-1 Release Date: 2026-08-04T11:39:06Z Rating: important References: * bsc#1271910 * bsc#1272414 Cross-References: * CVE-2026-61548 CVSS scores: * CVE-2026-61548 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for rsyslog fixes the following issues: * CVE-2026-61548: parsing of crafted RFC 5424 messages in `mmpstrucdata` can lead to a stack buffer overflow (bsc#1272414). * Configuration-dependent issue in the optional `imptcp` input module can allow an unauthenticated remote peer to crash `rsyslogd` (bsc#1271910). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3478=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3478=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3478=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rsyslog-module-snmp-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-pgsql-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-gssapi-8.2406.0-150700.3.7.1 * rsyslog-module-gtls-8.2406.0-150700.3.7.1 * rsyslog-module-relp-8.2406.0-150700.3.7.1 * rsyslog-module-mysql-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-snmp-8.2406.0-150700.3.7.1 * rsyslog-module-mmnormalize-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-pgsql-8.2406.0-150700.3.7.1 * rsyslog-module-udpspoof-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-udpspoof-8.2406.0-150700.3.7.1 * rsyslog-debugsource-8.2406.0-150700.3.7.1 * rsyslog-module-relp-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-gtls-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-mmnormalize-8.2406.0-150700.3.7.1 * rsyslog-module-mysql-8.2406.0-150700.3.7.1 * rsyslog-module-gssapi-debuginfo-8.2406.0-150700.3.7.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rsyslog-8.2406.0-150700.3.7.1 * rsyslog-debugsource-8.2406.0-150700.3.7.1 * rsyslog-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-ossl-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-ossl-8.2406.0-150700.3.7.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * rsyslog-debugsource-8.2406.0-150700.3.7.1 * rsyslog-module-kafka-8.2406.0-150700.3.7.1 * rsyslog-debuginfo-8.2406.0-150700.3.7.1 * rsyslog-module-kafka-debuginfo-8.2406.0-150700.3.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-61548.html * https://bugzilla.suse.com/show_bug.cgi?id=1271910 * https://bugzilla.suse.com/show_bug.cgi?id=1272414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 08:30:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 08:30:39 -0000 Subject: SUSE-SU-2026:3498-1: important: Security update for rsyslog Message-ID: <178591863909.17024.15964554108910116601@dac66d42c24b> # Security update for rsyslog Announcement ID: SUSE-SU-2026:3498-1 Release Date: 2026-08-04T17:53:40Z Rating: important References: * bsc#1271910 * bsc#1272414 Cross-References: * CVE-2026-61548 CVSS scores: * CVE-2026-61548 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for rsyslog fixes the following issues: * CVE-2026-61548: parsing of crafted RFC 5424 messages in `mmpstrucdata` can lead to a stack buffer overflow (bsc#1272414). * Configuration-dependent issue in the optional `imptcp` input module can allow an unauthenticated remote peer to crash `rsyslogd` (bsc#1271910). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3498=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3498=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rsyslog-module-pgsql-8.2106.0-8.22.1 * rsyslog-module-udpspoof-8.2106.0-8.22.1 * rsyslog-module-mmnormalize-debuginfo-8.2106.0-8.22.1 * rsyslog-module-snmp-debuginfo-8.2106.0-8.22.1 * rsyslog-debuginfo-8.2106.0-8.22.1 * rsyslog-module-gssapi-8.2106.0-8.22.1 * rsyslog-debugsource-8.2106.0-8.22.1 * rsyslog-doc-8.2106.0-8.22.1 * rsyslog-module-gtls-debuginfo-8.2106.0-8.22.1 * rsyslog-module-snmp-8.2106.0-8.22.1 * rsyslog-diag-tools-debuginfo-8.2106.0-8.22.1 * rsyslog-module-mmnormalize-8.2106.0-8.22.1 * rsyslog-module-mysql-debuginfo-8.2106.0-8.22.1 * rsyslog-module-udpspoof-debuginfo-8.2106.0-8.22.1 * rsyslog-8.2106.0-8.22.1 * rsyslog-diag-tools-8.2106.0-8.22.1 * rsyslog-module-relp-debuginfo-8.2106.0-8.22.1 * rsyslog-module-pgsql-debuginfo-8.2106.0-8.22.1 * rsyslog-module-relp-8.2106.0-8.22.1 * rsyslog-module-gssapi-debuginfo-8.2106.0-8.22.1 * rsyslog-module-gtls-8.2106.0-8.22.1 * rsyslog-module-mysql-8.2106.0-8.22.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * rsyslog-module-pgsql-8.2106.0-8.22.1 * rsyslog-module-udpspoof-8.2106.0-8.22.1 * rsyslog-module-mmnormalize-debuginfo-8.2106.0-8.22.1 * rsyslog-module-snmp-debuginfo-8.2106.0-8.22.1 * rsyslog-debuginfo-8.2106.0-8.22.1 * rsyslog-module-gssapi-8.2106.0-8.22.1 * rsyslog-debugsource-8.2106.0-8.22.1 * rsyslog-doc-8.2106.0-8.22.1 * rsyslog-module-gtls-debuginfo-8.2106.0-8.22.1 * rsyslog-module-snmp-8.2106.0-8.22.1 * rsyslog-diag-tools-debuginfo-8.2106.0-8.22.1 * rsyslog-module-mmnormalize-8.2106.0-8.22.1 * rsyslog-module-mysql-debuginfo-8.2106.0-8.22.1 * rsyslog-module-udpspoof-debuginfo-8.2106.0-8.22.1 * rsyslog-8.2106.0-8.22.1 * rsyslog-diag-tools-8.2106.0-8.22.1 * rsyslog-module-relp-debuginfo-8.2106.0-8.22.1 * rsyslog-module-pgsql-debuginfo-8.2106.0-8.22.1 * rsyslog-module-relp-8.2106.0-8.22.1 * rsyslog-module-gssapi-debuginfo-8.2106.0-8.22.1 * rsyslog-module-gtls-8.2106.0-8.22.1 * rsyslog-module-mysql-8.2106.0-8.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-61548.html * https://bugzilla.suse.com/show_bug.cgi?id=1271910 * https://bugzilla.suse.com/show_bug.cgi?id=1272414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 08:31:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 08:31:21 -0000 Subject: SUSE-SU-2026:3497-1: moderate: Security update for google-guest-agent Message-ID: <178591868164.17024.5608347620763867720@dac66d42c24b> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:3497-1 Release Date: 2026-08-04T16:18:46Z Rating: moderate References: * bsc#1272118 Cross-References: * CVE-2026-56852 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for google-guest-agent fixes the following issue: * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272118). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3497=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3497=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3497=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3497=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3497=1 ## Package List: * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.76.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.76.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.76.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.76.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260529.00-150000.1.76.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1272118 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 08:32:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 08:32:01 -0000 Subject: SUSE-SU-2026:3496-1: moderate: Security update for google-osconfig-agent Message-ID: <178591872106.17024.10561644130200450965@dac66d42c24b> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:3496-1 Release Date: 2026-08-04T16:18:02Z Rating: moderate References: * bsc#1272118 Cross-References: * CVE-2026-56852 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for google-osconfig-agent fixes the following issue: * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of input containing invalid UTF-8 bytes can lead to infinite loop (bsc#1272118). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3496=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260615.01-1.53.2 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1272118 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 18:14:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 18:14:45 -0000 Subject: SUSE-SU-2026:3500-1: critical: Security update for libXfont2 Message-ID: <178595368538.62.12038969701306143359@438c6482d549> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:3500-1 Release Date: 2026-08-05T11:58:00Z Rating: critical References: * bsc#1272660 * bsc#1272661 Cross-References: * CVE-2026-44950 * CVE-2026-59679 CVSS scores: * CVE-2026-44950 ( SUSE ): 9.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-44950 ( SUSE ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-59679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59679 ( SUSE ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues: * CVE-2026-44950: fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow (bsc#1272661). * CVE-2026-59679: fs_read_glyphs() heap OOB read/write via encoding array index mismatch (bsc#1272660). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3500=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3500=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3500=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3500=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3500=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3500=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3500=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3500=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3500=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3500=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3500=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libXfont2-devel-2.0.3-150000.3.6.1 * libXfont2-debugsource-2.0.3-150000.3.6.1 * libXfont2-2-2.0.3-150000.3.6.1 * libXfont2-2-debuginfo-2.0.3-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44950.html * https://www.suse.com/security/cve/CVE-2026-59679.html * https://bugzilla.suse.com/show_bug.cgi?id=1272660 * https://bugzilla.suse.com/show_bug.cgi?id=1272661 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 18:15:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 18:15:26 -0000 Subject: SUSE-SU-2026:3499-1: critical: Security update for libXfont2 Message-ID: <178595372631.62.17481468502910221102@438c6482d549> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:3499-1 Release Date: 2026-08-05T11:56:53Z Rating: critical References: * bsc#1272660 * bsc#1272661 Cross-References: * CVE-2026-44950 * CVE-2026-59679 CVSS scores: * CVE-2026-44950 ( SUSE ): 9.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-44950 ( SUSE ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-59679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59679 ( SUSE ): 9.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues: * CVE-2026-44950: fs_read_glyphs() heap buffer overflow via cumulative glyph data overflow (bsc#1272661). * CVE-2026-59679: fs_read_glyphs() heap OOB read/write via encoding array index mismatch (bsc#1272660). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3499=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3499=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libXfont2-debugsource-2.0.3-3.6.1 * libXfont2-2-debuginfo-2.0.3-3.6.1 * libXfont2-2-2.0.3-3.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libXfont2-debugsource-2.0.3-3.6.1 * libXfont2-2-debuginfo-2.0.3-3.6.1 * libXfont2-2-2.0.3-3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44950.html * https://www.suse.com/security/cve/CVE-2026-59679.html * https://bugzilla.suse.com/show_bug.cgi?id=1272660 * https://bugzilla.suse.com/show_bug.cgi?id=1272661 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:30:41 -0000 Subject: SUSE-SU-2026:3512-1: moderate: Security update for evince Message-ID: <178596184125.471.10190841952905408062@dac66d42c24b> # Security update for evince Announcement ID: SUSE-SU-2026:3512-1 Release Date: 2026-08-05T18:03:36Z Rating: moderate References: * bsc#1272433 Cross-References: * CVE-2026-63729 CVSS scores: * CVE-2026-63729 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63729 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-63729 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63729 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for evince fixes the following issue: * CVE-2026-63729: texlive: heap use-after-free in `synctex_parser.c` via a malformed `.synctex` or `.synctex.gz` file (bsc#1272433). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3512=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3512=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * evince-plugin-pdfdocument-debuginfo-45.0-150600.3.6.1 * libevview3-3-debuginfo-45.0-150600.3.6.1 * evince-plugin-dvidocument-45.0-150600.3.6.1 * evince-plugin-tiffdocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-djvudocument-45.0-150600.3.6.1 * libevdocument3-4-45.0-150600.3.6.1 * evince-plugin-xpsdocument-45.0-150600.3.6.1 * evince-debuginfo-45.0-150600.3.6.1 * typelib-1_0-EvinceDocument-3_0-45.0-150600.3.6.1 * evince-plugin-dvidocument-debuginfo-45.0-150600.3.6.1 * libevview3-3-45.0-150600.3.6.1 * evince-plugin-psdocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-xpsdocument-debuginfo-45.0-150600.3.6.1 * evince-debugsource-45.0-150600.3.6.1 * typelib-1_0-EvinceView-3_0-45.0-150600.3.6.1 * evince-devel-45.0-150600.3.6.1 * evince-plugin-psdocument-45.0-150600.3.6.1 * evince-plugin-tiffdocument-45.0-150600.3.6.1 * evince-45.0-150600.3.6.1 * evince-plugin-djvudocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-pdfdocument-45.0-150600.3.6.1 * libevdocument3-4-debuginfo-45.0-150600.3.6.1 * evince-plugin-comicsdocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-comicsdocument-45.0-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * evince-lang-45.0-150600.3.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * evince-plugin-pdfdocument-debuginfo-45.0-150600.3.6.1 * libevview3-3-debuginfo-45.0-150600.3.6.1 * evince-plugin-dvidocument-45.0-150600.3.6.1 * evince-plugin-tiffdocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-djvudocument-45.0-150600.3.6.1 * libevdocument3-4-45.0-150600.3.6.1 * evince-plugin-xpsdocument-45.0-150600.3.6.1 * evince-debuginfo-45.0-150600.3.6.1 * typelib-1_0-EvinceDocument-3_0-45.0-150600.3.6.1 * evince-plugin-dvidocument-debuginfo-45.0-150600.3.6.1 * libevview3-3-45.0-150600.3.6.1 * evince-plugin-psdocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-xpsdocument-debuginfo-45.0-150600.3.6.1 * evince-debugsource-45.0-150600.3.6.1 * typelib-1_0-EvinceView-3_0-45.0-150600.3.6.1 * evince-devel-45.0-150600.3.6.1 * evince-plugin-psdocument-45.0-150600.3.6.1 * evince-plugin-tiffdocument-45.0-150600.3.6.1 * evince-45.0-150600.3.6.1 * evince-plugin-djvudocument-debuginfo-45.0-150600.3.6.1 * evince-plugin-pdfdocument-45.0-150600.3.6.1 * libevdocument3-4-debuginfo-45.0-150600.3.6.1 * Desktop Applications Module 15-SP7 (noarch) * evince-lang-45.0-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63729.html * https://bugzilla.suse.com/show_bug.cgi?id=1272433 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:32:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:32:18 -0000 Subject: SUSE-SU-2026:3510-1: critical: Security update for php7 Message-ID: <178596193855.471.7640752126961255527@dac66d42c24b> # Security update for php7 Announcement ID: SUSE-SU-2026:3510-1 Release Date: 2026-08-05T13:50:17Z Rating: critical References: * bsc#1273075 * bsc#1273077 * bsc#1273078 Cross-References: * CVE-2026-17543 * CVE-2026-7260 * CVE-2026-9672 CVSS scores: * CVE-2026-17543 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-17543 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-17543 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X * CVE-2026-17543 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7260 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7260 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9672 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for php7 fixes the following issues: * CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). * CVE-2026-9672: security issues in `libgd` (bsc#1273078). * CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3510=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3510=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3510=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3510=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3510=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3510=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3510=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3510=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3510=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3510=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3510=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-embed-debugsource-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * php7-embed-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-embed-debuginfo-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-test-7.4.33-150400.4.68.2 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-embed-debugsource-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * php7-embed-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-embed-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-test-7.4.33-150400.4.68.2 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * php7-pcntl-7.4.33-150400.4.68.1 * php7-opcache-7.4.33-150400.4.68.1 * php7-sysvsem-7.4.33-150400.4.68.1 * php7-dba-7.4.33-150400.4.68.1 * php7-pgsql-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-debugsource-7.4.33-150400.4.68.1 * php7-gmp-debuginfo-7.4.33-150400.4.68.1 * php7-intl-7.4.33-150400.4.68.1 * php7-sodium-7.4.33-150400.4.68.1 * php7-cli-7.4.33-150400.4.68.1 * php7-calendar-7.4.33-150400.4.68.1 * php7-xsl-debuginfo-7.4.33-150400.4.68.1 * php7-sqlite-7.4.33-150400.4.68.1 * php7-fastcgi-debugsource-7.4.33-150400.4.68.1 * php7-bcmath-7.4.33-150400.4.68.1 * php7-iconv-7.4.33-150400.4.68.1 * php7-fpm-debuginfo-7.4.33-150400.4.68.1 * php7-mbstring-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-debuginfo-7.4.33-150400.4.68.1 * php7-enchant-debuginfo-7.4.33-150400.4.68.1 * php7-gettext-7.4.33-150400.4.68.1 * php7-iconv-debuginfo-7.4.33-150400.4.68.1 * php7-calendar-debuginfo-7.4.33-150400.4.68.1 * php7-zip-7.4.33-150400.4.68.1 * php7-snmp-debuginfo-7.4.33-150400.4.68.1 * php7-xmlreader-7.4.33-150400.4.68.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.68.1 * php7-dom-debuginfo-7.4.33-150400.4.68.1 * php7-readline-7.4.33-150400.4.68.1 * php7-pdo-debuginfo-7.4.33-150400.4.68.1 * php7-zlib-7.4.33-150400.4.68.1 * php7-posix-7.4.33-150400.4.68.1 * php7-gettext-debuginfo-7.4.33-150400.4.68.1 * php7-sodium-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-7.4.33-150400.4.68.1 * php7-phar-7.4.33-150400.4.68.1 * php7-bcmath-debuginfo-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * php7-zip-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.68.1 * php7-odbc-7.4.33-150400.4.68.1 * php7-sqlite-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-7.4.33-150400.4.68.1 * php7-ldap-debuginfo-7.4.33-150400.4.68.1 * php7-devel-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * php7-ctype-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-mbstring-7.4.33-150400.4.68.1 * php7-shmop-debuginfo-7.4.33-150400.4.68.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-7.4.33-150400.4.68.1 * php7-exif-7.4.33-150400.4.68.1 * php7-json-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.68.1 * php7-openssl-debuginfo-7.4.33-150400.4.68.1 * php7-curl-debuginfo-7.4.33-150400.4.68.1 * php7-tokenizer-7.4.33-150400.4.68.1 * php7-soap-debuginfo-7.4.33-150400.4.68.1 * php7-gd-7.4.33-150400.4.68.1 * php7-sysvshm-7.4.33-150400.4.68.1 * php7-posix-debuginfo-7.4.33-150400.4.68.1 * php7-snmp-7.4.33-150400.4.68.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.68.1 * php7-pgsql-7.4.33-150400.4.68.1 * php7-dom-7.4.33-150400.4.68.1 * php7-pcntl-debuginfo-7.4.33-150400.4.68.1 * php7-dba-debuginfo-7.4.33-150400.4.68.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.68.1 * php7-bz2-7.4.33-150400.4.68.1 * php7-pdo-7.4.33-150400.4.68.1 * php7-intl-debuginfo-7.4.33-150400.4.68.1 * php7-tidy-debuginfo-7.4.33-150400.4.68.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.68.1 * php7-mysql-7.4.33-150400.4.68.1 * php7-xsl-7.4.33-150400.4.68.1 * php7-phar-debuginfo-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 * php7-gmp-7.4.33-150400.4.68.1 * php7-enchant-7.4.33-150400.4.68.1 * php7-cli-debuginfo-7.4.33-150400.4.68.1 * php7-ctype-debuginfo-7.4.33-150400.4.68.1 * php7-ldap-7.4.33-150400.4.68.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.68.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.68.1 * php7-fastcgi-7.4.33-150400.4.68.1 * php7-tidy-7.4.33-150400.4.68.1 * php7-debugsource-7.4.33-150400.4.68.1 * php7-sysvmsg-7.4.33-150400.4.68.1 * php7-soap-7.4.33-150400.4.68.1 * php7-sockets-7.4.33-150400.4.68.1 * php7-mysql-debuginfo-7.4.33-150400.4.68.1 * php7-json-7.4.33-150400.4.68.1 * php7-zlib-debuginfo-7.4.33-150400.4.68.1 * php7-sockets-debuginfo-7.4.33-150400.4.68.1 * php7-ftp-debuginfo-7.4.33-150400.4.68.1 * php7-gd-debuginfo-7.4.33-150400.4.68.1 * php7-xmlrpc-7.4.33-150400.4.68.1 * php7-exif-debuginfo-7.4.33-150400.4.68.1 * php7-curl-7.4.33-150400.4.68.1 * php7-opcache-debuginfo-7.4.33-150400.4.68.1 * php7-fileinfo-7.4.33-150400.4.68.1 * php7-odbc-debuginfo-7.4.33-150400.4.68.1 * php7-fpm-7.4.33-150400.4.68.1 * php7-shmop-7.4.33-150400.4.68.1 * php7-readline-debuginfo-7.4.33-150400.4.68.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * php7-debugsource-7.4.33-150400.4.68.1 * php7-7.4.33-150400.4.68.1 * apache2-mod_php7-7.4.33-150400.4.68.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.68.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.68.1 * php7-debuginfo-7.4.33-150400.4.68.1 ## References: * https://www.suse.com/security/cve/CVE-2026-17543.html * https://www.suse.com/security/cve/CVE-2026-7260.html * https://www.suse.com/security/cve/CVE-2026-9672.html * https://bugzilla.suse.com/show_bug.cgi?id=1273075 * https://bugzilla.suse.com/show_bug.cgi?id=1273077 * https://bugzilla.suse.com/show_bug.cgi?id=1273078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:33:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:33:17 -0000 Subject: SUSE-SU-2026:3509-1: critical: Security update for php8 Message-ID: <178596199797.471.1007754527500059125@dac66d42c24b> # Security update for php8 Announcement ID: SUSE-SU-2026:3509-1 Release Date: 2026-08-05T13:48:22Z Rating: critical References: * bsc#1273075 * bsc#1273077 * bsc#1273078 Cross-References: * CVE-2026-17543 * CVE-2026-7260 * CVE-2026-9672 CVSS scores: * CVE-2026-17543 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-17543 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-17543 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X * CVE-2026-17543 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7260 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7260 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9672 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for php8 fixes the following issues: Update to version 8.3.33. Security issues fixed: * CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). * CVE-2026-9672: security issues in `libgd` (bsc#1273078). * CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3509=1 ## Package List: * Web and Scripting Module 15-SP7 (aarch64 ppc64le s390x x86_64) * php8-exif-debuginfo-8.3.33-150700.3.18.1 * php8-fpm-debugsource-8.3.33-150700.3.18.1 * php8-dom-debuginfo-8.3.33-150700.3.18.1 * php8-curl-debuginfo-8.3.33-150700.3.18.1 * php8-iconv-debuginfo-8.3.33-150700.3.18.1 * php8-embed-8.3.33-150700.3.18.1 * php8-sockets-debuginfo-8.3.33-150700.3.18.1 * php8-enchant-debuginfo-8.3.33-150700.3.18.1 * php8-gd-debuginfo-8.3.33-150700.3.18.1 * php8-ftp-debuginfo-8.3.33-150700.3.18.1 * php8-pgsql-debuginfo-8.3.33-150700.3.18.1 * php8-ctype-8.3.33-150700.3.18.1 * php8-cli-debuginfo-8.3.33-150700.3.18.1 * php8-sodium-debuginfo-8.3.33-150700.3.18.1 * php8-xmlreader-8.3.33-150700.3.18.1 * php8-bz2-debuginfo-8.3.33-150700.3.18.1 * php8-fileinfo-8.3.33-150700.3.18.1 * php8-sockets-8.3.33-150700.3.18.1 * php8-gd-8.3.33-150700.3.18.1 * php8-bcmath-debuginfo-8.3.33-150700.3.18.1 * php8-fastcgi-debuginfo-8.3.33-150700.3.18.1 * php8-ctype-debuginfo-8.3.33-150700.3.18.1 * php8-fastcgi-8.3.33-150700.3.18.1 * php8-gmp-8.3.33-150700.3.18.1 * php8-sysvsem-8.3.33-150700.3.18.1 * php8-sysvshm-8.3.33-150700.3.18.1 * php8-shmop-8.3.33-150700.3.18.1 * php8-sodium-8.3.33-150700.3.18.1 * php8-xmlwriter-8.3.33-150700.3.18.1 * php8-xmlreader-debuginfo-8.3.33-150700.3.18.1 * php8-pdo-8.3.33-150700.3.18.1 * php8-ldap-debuginfo-8.3.33-150700.3.18.1 * php8-zlib-debuginfo-8.3.33-150700.3.18.1 * php8-fpm-debuginfo-8.3.33-150700.3.18.1 * php8-soap-debuginfo-8.3.33-150700.3.18.1 * php8-snmp-8.3.33-150700.3.18.1 * php8-zlib-8.3.33-150700.3.18.1 * php8-phar-8.3.33-150700.3.18.1 * php8-gmp-debuginfo-8.3.33-150700.3.18.1 * php8-pgsql-8.3.33-150700.3.18.1 * php8-gettext-8.3.33-150700.3.18.1 * php8-pcntl-debuginfo-8.3.33-150700.3.18.1 * php8-cli-8.3.33-150700.3.18.1 * php8-pdo-debuginfo-8.3.33-150700.3.18.1 * php8-tokenizer-8.3.33-150700.3.18.1 * apache2-mod_php8-8.3.33-150700.3.18.1 * php8-tidy-8.3.33-150700.3.18.1 * php8-curl-8.3.33-150700.3.18.1 * php8-posix-debuginfo-8.3.33-150700.3.18.1 * php8-opcache-debuginfo-8.3.33-150700.3.18.1 * php8-ldap-8.3.33-150700.3.18.1 * php8-fpm-8.3.33-150700.3.18.1 * php8-pcntl-8.3.33-150700.3.18.1 * php8-mysql-8.3.33-150700.3.18.1 * php8-readline-8.3.33-150700.3.18.1 * php8-odbc-debuginfo-8.3.33-150700.3.18.1 * php8-shmop-debuginfo-8.3.33-150700.3.18.1 * php8-phar-debuginfo-8.3.33-150700.3.18.1 * php8-openssl-debuginfo-8.3.33-150700.3.18.1 * php8-bcmath-8.3.33-150700.3.18.1 * php8-iconv-8.3.33-150700.3.18.1 * php8-sysvmsg-8.3.33-150700.3.18.1 * php8-snmp-debuginfo-8.3.33-150700.3.18.1 * php8-opcache-8.3.33-150700.3.18.1 * php8-zip-debuginfo-8.3.33-150700.3.18.1 * php8-openssl-8.3.33-150700.3.18.1 * php8-soap-8.3.33-150700.3.18.1 * php8-fileinfo-debuginfo-8.3.33-150700.3.18.1 * php8-calendar-8.3.33-150700.3.18.1 * php8-test-8.3.33-150700.3.18.1 * apache2-mod_php8-debuginfo-8.3.33-150700.3.18.1 * php8-xsl-debuginfo-8.3.33-150700.3.18.1 * php8-bz2-8.3.33-150700.3.18.1 * php8-dba-8.3.33-150700.3.18.1 * php8-dba-debuginfo-8.3.33-150700.3.18.1 * php8-posix-8.3.33-150700.3.18.1 * php8-enchant-8.3.33-150700.3.18.1 * php8-intl-8.3.33-150700.3.18.1 * apache2-mod_php8-debugsource-8.3.33-150700.3.18.1 * php8-odbc-8.3.33-150700.3.18.1 * php8-sysvshm-debuginfo-8.3.33-150700.3.18.1 * php8-sqlite-debuginfo-8.3.33-150700.3.18.1 * php8-mbstring-debuginfo-8.3.33-150700.3.18.1 * php8-exif-8.3.33-150700.3.18.1 * php8-mbstring-8.3.33-150700.3.18.1 * php8-tokenizer-debuginfo-8.3.33-150700.3.18.1 * php8-debugsource-8.3.33-150700.3.18.1 * php8-sqlite-8.3.33-150700.3.18.1 * php8-dom-8.3.33-150700.3.18.1 * php8-embed-debuginfo-8.3.33-150700.3.18.1 * php8-ftp-8.3.33-150700.3.18.1 * php8-intl-debuginfo-8.3.33-150700.3.18.1 * php8-debuginfo-8.3.33-150700.3.18.1 * php8-fastcgi-debugsource-8.3.33-150700.3.18.1 * php8-devel-8.3.33-150700.3.18.1 * php8-xsl-8.3.33-150700.3.18.1 * php8-sysvmsg-debuginfo-8.3.33-150700.3.18.1 * php8-calendar-debuginfo-8.3.33-150700.3.18.1 * php8-tidy-debuginfo-8.3.33-150700.3.18.1 * php8-8.3.33-150700.3.18.1 * php8-xmlwriter-debuginfo-8.3.33-150700.3.18.1 * php8-zip-8.3.33-150700.3.18.1 * php8-sysvsem-debuginfo-8.3.33-150700.3.18.1 * php8-mysql-debuginfo-8.3.33-150700.3.18.1 * php8-readline-debuginfo-8.3.33-150700.3.18.1 * php8-embed-debugsource-8.3.33-150700.3.18.1 * php8-gettext-debuginfo-8.3.33-150700.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-17543.html * https://www.suse.com/security/cve/CVE-2026-7260.html * https://www.suse.com/security/cve/CVE-2026-9672.html * https://bugzilla.suse.com/show_bug.cgi?id=1273075 * https://bugzilla.suse.com/show_bug.cgi?id=1273077 * https://bugzilla.suse.com/show_bug.cgi?id=1273078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:34:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:34:06 -0000 Subject: SUSE-SU-2026:3508-1: critical: Security update for pcp Message-ID: <178596204669.471.8581890347900174066@dac66d42c24b> # Security update for pcp Announcement ID: SUSE-SU-2026:3508-1 Release Date: 2026-08-05T13:21:27Z Rating: critical References: * bsc#1272922 * bsc#1272923 * bsc#1272924 * bsc#1272925 * bsc#1272926 * bsc#1272927 * bsc#1272928 * bsc#1272930 Cross-References: * CVE-2026-16524 * CVE-2026-16526 * CVE-2026-16527 * CVE-2026-16529 * CVE-2026-16530 * CVE-2026-16531 CVSS scores: * CVE-2026-16524 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16524 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16527 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-16527 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-16527 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-16529 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16529 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16529 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16530 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16530 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-16530 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16531 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-16531 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-16531 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). * CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). * CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). * CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). * CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). * CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). * Command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928). * Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3508=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3508=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * pcp-devel-6.2.0-6.32.1 * pcp-devel-debuginfo-6.2.0-6.32.1 * libpcp-devel-6.2.0-6.32.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * pcp-devel-6.2.0-6.32.1 * pcp-devel-debuginfo-6.2.0-6.32.1 * libpcp-devel-6.2.0-6.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16524.html * https://www.suse.com/security/cve/CVE-2026-16526.html * https://www.suse.com/security/cve/CVE-2026-16527.html * https://www.suse.com/security/cve/CVE-2026-16529.html * https://www.suse.com/security/cve/CVE-2026-16530.html * https://www.suse.com/security/cve/CVE-2026-16531.html * https://bugzilla.suse.com/show_bug.cgi?id=1272922 * https://bugzilla.suse.com/show_bug.cgi?id=1272923 * https://bugzilla.suse.com/show_bug.cgi?id=1272924 * https://bugzilla.suse.com/show_bug.cgi?id=1272925 * https://bugzilla.suse.com/show_bug.cgi?id=1272926 * https://bugzilla.suse.com/show_bug.cgi?id=1272927 * https://bugzilla.suse.com/show_bug.cgi?id=1272928 * https://bugzilla.suse.com/show_bug.cgi?id=1272930 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:34:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:34:55 -0000 Subject: SUSE-SU-2026:3507-1: critical: Security update for pcp Message-ID: <178596209590.471.17477973190178769887@dac66d42c24b> # Security update for pcp Announcement ID: SUSE-SU-2026:3507-1 Release Date: 2026-08-05T13:20:37Z Rating: critical References: * bsc#1272922 * bsc#1272923 * bsc#1272924 * bsc#1272925 * bsc#1272926 * bsc#1272927 * bsc#1272928 * bsc#1272930 Cross-References: * CVE-2026-16524 * CVE-2026-16526 * CVE-2026-16527 * CVE-2026-16529 * CVE-2026-16530 * CVE-2026-16531 CVSS scores: * CVE-2026-16524 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16524 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16527 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-16527 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-16527 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-16529 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16529 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16529 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16530 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16530 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-16530 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16531 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-16531 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-16531 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). * CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). * CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). * CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). * CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). * CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). * Command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928). * Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3507=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3507=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3507=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3507=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * pcp-pmda-cisco-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-roomtemp-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-trace-6.2.0-150600.3.12.1 * pcp-system-tools-6.2.0-150600.3.12.1 * pcp-pmda-mounts-6.2.0-150600.3.12.1 * pcp-debugsource-6.2.0-150600.3.12.1 * pcp-import-collectl2pcp-6.2.0-150600.3.12.1 * pcp-pmda-zimbra-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-lustrecomm-6.2.0-150600.3.12.1 * perl-PCP-LogImport-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-bind2-6.2.0-150600.3.12.1 * libpcp-devel-6.2.0-150600.3.12.1 * pcp-pmda-bash-debuginfo-6.2.0-150600.3.12.1 * libpcp_mmv1-6.2.0-150600.3.12.1 * pcp-pmda-cifs-6.2.0-150600.3.12.1 * pcp-pmda-gfs2-6.2.0-150600.3.12.1 * pcp-pmda-sendmail-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-summary-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-zimbra-6.2.0-150600.3.12.1 * pcp-pmda-summary-6.2.0-150600.3.12.1 * pcp-pmda-shping-debuginfo-6.2.0-150600.3.12.1 * pcp-devel-6.2.0-150600.3.12.1 * pcp-pmda-nvidia-gpu-6.2.0-150600.3.12.1 * perl-PCP-MMV-debuginfo-6.2.0-150600.3.12.1 * pcp-testsuite-debuginfo-6.2.0-150600.3.12.1 * libpcp_mmv1-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-logger-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-shping-6.2.0-150600.3.12.1 * libpcp_trace2-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-PMDA-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-MMV-6.2.0-150600.3.12.1 * libpcp_gui2-6.2.0-150600.3.12.1 * python3-pcp-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-systemd-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-sendmail-6.2.0-150600.3.12.1 * libpcp_gui2-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-LogImport-6.2.0-150600.3.12.1 * python3-pcp-6.2.0-150600.3.12.1 * pcp-pmda-smart-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-apache-debuginfo-6.2.0-150600.3.12.1 * libpcp3-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-logger-6.2.0-150600.3.12.1 * pcp-pmda-docker-6.2.0-150600.3.12.1 * libpcp_web1-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-weblog-debuginfo-6.2.0-150600.3.12.1 * pcp-6.2.0-150600.3.12.1 * pcp-pmda-mounts-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-systemd-6.2.0-150600.3.12.1 * pcp-pmda-mailq-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-smart-6.2.0-150600.3.12.1 * pcp-pmda-hacluster-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-mailq-6.2.0-150600.3.12.1 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150600.3.12.1 * libpcp_trace2-6.2.0-150600.3.12.1 * pcp-system-tools-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-PMDA-6.2.0-150600.3.12.1 * libpcp_import1-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-bash-6.2.0-150600.3.12.1 * pcp-pmda-trace-debuginfo-6.2.0-150600.3.12.1 * libpcp_web1-6.2.0-150600.3.12.1 * pcp-pmda-sockets-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-hacluster-6.2.0-150600.3.12.1 * libpcp3-6.2.0-150600.3.12.1 * pcp-pmda-gfs2-debuginfo-6.2.0-150600.3.12.1 * pcp-testsuite-6.2.0-150600.3.12.1 * pcp-devel-debuginfo-6.2.0-150600.3.12.1 * pcp-import-collectl2pcp-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-roomtemp-6.2.0-150600.3.12.1 * pcp-pmda-cisco-6.2.0-150600.3.12.1 * pcp-pmda-dm-6.2.0-150600.3.12.1 * pcp-pmda-weblog-6.2.0-150600.3.12.1 * perl-PCP-LogSummary-6.2.0-150600.3.12.1 * pcp-pmda-apache-6.2.0-150600.3.12.1 * pcp-debuginfo-6.2.0-150600.3.12.1 * pcp-gui-6.2.0-150600.3.12.1 * pcp-pmda-cifs-debuginfo-6.2.0-150600.3.12.1 * pcp-gui-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-dm-debuginfo-6.2.0-150600.3.12.1 * libpcp_import1-6.2.0-150600.3.12.1 * pcp-pmda-docker-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-sockets-6.2.0-150600.3.12.1 * openSUSE Leap 15.6 (noarch) * pcp-pmda-rabbitmq-6.2.0-150600.3.12.1 * pcp-pmda-named-6.2.0-150600.3.12.1 * pcp-pmda-json-6.2.0-150600.3.12.1 * pcp-pmda-nfsclient-6.2.0-150600.3.12.1 * pcp-export-pcp2graphite-6.2.0-150600.3.12.1 * pcp-pmda-nginx-6.2.0-150600.3.12.1 * pcp-import-iostat2pcp-6.2.0-150600.3.12.1 * pcp-pmda-redis-6.2.0-150600.3.12.1 * pcp-pmda-samba-6.2.0-150600.3.12.1 * pcp-pmda-netcheck-6.2.0-150600.3.12.1 * pcp-pmda-zswap-6.2.0-150600.3.12.1 * pcp-pmda-bonding-6.2.0-150600.3.12.1 * pcp-export-pcp2elasticsearch-6.2.0-150600.3.12.1 * pcp-pmda-ds389log-6.2.0-150600.3.12.1 * pcp-pmda-dbping-6.2.0-150600.3.12.1 * pcp-pmda-gpfs-6.2.0-150600.3.12.1 * pcp-pmda-rsyslog-6.2.0-150600.3.12.1 * pcp-pmda-openmetrics-6.2.0-150600.3.12.1 * pcp-import-ganglia2pcp-6.2.0-150600.3.12.1 * pcp-import-sar2pcp-6.2.0-150600.3.12.1 * pcp-export-pcp2json-6.2.0-150600.3.12.1 * pcp-pmda-unbound-6.2.0-150600.3.12.1 * pcp-pmda-nutcracker-6.2.0-150600.3.12.1 * pcp-pmda-lmsensors-6.2.0-150600.3.12.1 * pcp-export-pcp2xml-6.2.0-150600.3.12.1 * pcp-pmda-lustre-6.2.0-150600.3.12.1 * pcp-pmda-snmp-6.2.0-150600.3.12.1 * pcp-conf-6.2.0-150600.3.12.1 * pcp-pmda-postfix-6.2.0-150600.3.12.1 * pcp-pmda-pdns-6.2.0-150600.3.12.1 * pcp-doc-6.2.0-150600.3.12.1 * pcp-pmda-mic-6.2.0-150600.3.12.1 * pcp-pmda-netfilter-6.2.0-150600.3.12.1 * pcp-zeroconf-6.2.0-150600.3.12.1 * pcp-pmda-slurm-6.2.0-150600.3.12.1 * pcp-pmda-openvswitch-6.2.0-150600.3.12.1 * pcp-import-mrtg2pcp-6.2.0-150600.3.12.1 * pcp-pmda-memcache-6.2.0-150600.3.12.1 * pcp-pmda-news-6.2.0-150600.3.12.1 * pcp-pmda-haproxy-6.2.0-150600.3.12.1 * pcp-pmda-gpsd-6.2.0-150600.3.12.1 * pcp-export-pcp2spark-6.2.0-150600.3.12.1 * pcp-pmda-activemq-6.2.0-150600.3.12.1 * pcp-export-pcp2zabbix-6.2.0-150600.3.12.1 * pcp-pmda-oracle-6.2.0-150600.3.12.1 * pcp-pmda-gluster-6.2.0-150600.3.12.1 * pcp-pmda-elasticsearch-6.2.0-150600.3.12.1 * pcp-pmda-mysql-6.2.0-150600.3.12.1 * pcp-pmda-ds389-6.2.0-150600.3.12.1 * pcp-export-pcp2influxdb-6.2.0-150600.3.12.1 * openSUSE Leap 15.6 (x86_64) * pcp-pmda-resctrl-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-resctrl-6.2.0-150600.3.12.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le x86_64) * pcp-pmda-perfevent-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-infiniband-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-perfevent-6.2.0-150600.3.12.1 * pcp-pmda-infiniband-6.2.0-150600.3.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * pcp-system-tools-6.2.0-150600.3.12.1 * libpcp_web1-debuginfo-6.2.0-150600.3.12.1 * pcp-6.2.0-150600.3.12.1 * pcp-debugsource-6.2.0-150600.3.12.1 * pcp-devel-6.2.0-150600.3.12.1 * perl-PCP-LogSummary-6.2.0-150600.3.12.1 * perl-PCP-MMV-debuginfo-6.2.0-150600.3.12.1 * pcp-debuginfo-6.2.0-150600.3.12.1 * libpcp_mmv1-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-LogImport-debuginfo-6.2.0-150600.3.12.1 * libpcp-devel-6.2.0-150600.3.12.1 * pcp-system-tools-debuginfo-6.2.0-150600.3.12.1 * libpcp_trace2-6.2.0-150600.3.12.1 * perl-PCP-PMDA-6.2.0-150600.3.12.1 * libpcp_import1-debuginfo-6.2.0-150600.3.12.1 * libpcp_trace2-debuginfo-6.2.0-150600.3.12.1 * libpcp_web1-6.2.0-150600.3.12.1 * perl-PCP-PMDA-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-MMV-6.2.0-150600.3.12.1 * libpcp_gui2-6.2.0-150600.3.12.1 * python3-pcp-debuginfo-6.2.0-150600.3.12.1 * libpcp_import1-6.2.0-150600.3.12.1 * libpcp_mmv1-6.2.0-150600.3.12.1 * libpcp_gui2-debuginfo-6.2.0-150600.3.12.1 * python3-pcp-6.2.0-150600.3.12.1 * perl-PCP-LogImport-6.2.0-150600.3.12.1 * libpcp3-6.2.0-150600.3.12.1 * libpcp3-debuginfo-6.2.0-150600.3.12.1 * pcp-devel-debuginfo-6.2.0-150600.3.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le) * pcp-pmda-perfevent-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-perfevent-6.2.0-150600.3.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * pcp-conf-6.2.0-150600.3.12.1 * pcp-doc-6.2.0-150600.3.12.1 * pcp-import-iostat2pcp-6.2.0-150600.3.12.1 * pcp-import-sar2pcp-6.2.0-150600.3.12.1 * pcp-import-mrtg2pcp-6.2.0-150600.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * pcp-system-tools-6.2.0-150600.3.12.1 * libpcp_web1-debuginfo-6.2.0-150600.3.12.1 * pcp-6.2.0-150600.3.12.1 * pcp-debugsource-6.2.0-150600.3.12.1 * pcp-devel-6.2.0-150600.3.12.1 * perl-PCP-LogSummary-6.2.0-150600.3.12.1 * perl-PCP-MMV-debuginfo-6.2.0-150600.3.12.1 * pcp-debuginfo-6.2.0-150600.3.12.1 * libpcp_mmv1-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-LogImport-debuginfo-6.2.0-150600.3.12.1 * libpcp-devel-6.2.0-150600.3.12.1 * pcp-system-tools-debuginfo-6.2.0-150600.3.12.1 * libpcp_trace2-6.2.0-150600.3.12.1 * perl-PCP-PMDA-6.2.0-150600.3.12.1 * libpcp_import1-debuginfo-6.2.0-150600.3.12.1 * libpcp_web1-6.2.0-150600.3.12.1 * libpcp_trace2-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-PMDA-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-MMV-6.2.0-150600.3.12.1 * libpcp_gui2-6.2.0-150600.3.12.1 * python3-pcp-debuginfo-6.2.0-150600.3.12.1 * libpcp_mmv1-6.2.0-150600.3.12.1 * libpcp_import1-6.2.0-150600.3.12.1 * libpcp_gui2-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-LogImport-6.2.0-150600.3.12.1 * python3-pcp-6.2.0-150600.3.12.1 * libpcp3-6.2.0-150600.3.12.1 * libpcp3-debuginfo-6.2.0-150600.3.12.1 * pcp-devel-debuginfo-6.2.0-150600.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * pcp-conf-6.2.0-150600.3.12.1 * pcp-doc-6.2.0-150600.3.12.1 * pcp-import-iostat2pcp-6.2.0-150600.3.12.1 * pcp-import-sar2pcp-6.2.0-150600.3.12.1 * pcp-import-mrtg2pcp-6.2.0-150600.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le) * pcp-pmda-perfevent-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-perfevent-6.2.0-150600.3.12.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * pcp-system-tools-6.2.0-150600.3.12.1 * libpcp_web1-debuginfo-6.2.0-150600.3.12.1 * pcp-6.2.0-150600.3.12.1 * pcp-debugsource-6.2.0-150600.3.12.1 * pcp-devel-6.2.0-150600.3.12.1 * perl-PCP-LogSummary-6.2.0-150600.3.12.1 * perl-PCP-MMV-debuginfo-6.2.0-150600.3.12.1 * pcp-debuginfo-6.2.0-150600.3.12.1 * libpcp_mmv1-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-LogImport-debuginfo-6.2.0-150600.3.12.1 * libpcp-devel-6.2.0-150600.3.12.1 * pcp-system-tools-debuginfo-6.2.0-150600.3.12.1 * libpcp_trace2-6.2.0-150600.3.12.1 * perl-PCP-PMDA-6.2.0-150600.3.12.1 * libpcp_import1-debuginfo-6.2.0-150600.3.12.1 * libpcp_web1-6.2.0-150600.3.12.1 * libpcp_trace2-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-PMDA-debuginfo-6.2.0-150600.3.12.1 * libpcp_gui2-6.2.0-150600.3.12.1 * perl-PCP-MMV-6.2.0-150600.3.12.1 * python3-pcp-debuginfo-6.2.0-150600.3.12.1 * libpcp_import1-6.2.0-150600.3.12.1 * libpcp_mmv1-6.2.0-150600.3.12.1 * python3-pcp-6.2.0-150600.3.12.1 * libpcp_gui2-debuginfo-6.2.0-150600.3.12.1 * perl-PCP-LogImport-6.2.0-150600.3.12.1 * libpcp3-6.2.0-150600.3.12.1 * libpcp3-debuginfo-6.2.0-150600.3.12.1 * pcp-devel-debuginfo-6.2.0-150600.3.12.1 * Development Tools Module 15-SP7 (noarch) * pcp-conf-6.2.0-150600.3.12.1 * pcp-doc-6.2.0-150600.3.12.1 * pcp-import-iostat2pcp-6.2.0-150600.3.12.1 * pcp-import-sar2pcp-6.2.0-150600.3.12.1 * pcp-import-mrtg2pcp-6.2.0-150600.3.12.1 * Development Tools Module 15-SP7 (ppc64le) * pcp-pmda-perfevent-debuginfo-6.2.0-150600.3.12.1 * pcp-pmda-perfevent-6.2.0-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16524.html * https://www.suse.com/security/cve/CVE-2026-16526.html * https://www.suse.com/security/cve/CVE-2026-16527.html * https://www.suse.com/security/cve/CVE-2026-16529.html * https://www.suse.com/security/cve/CVE-2026-16530.html * https://www.suse.com/security/cve/CVE-2026-16531.html * https://bugzilla.suse.com/show_bug.cgi?id=1272922 * https://bugzilla.suse.com/show_bug.cgi?id=1272923 * https://bugzilla.suse.com/show_bug.cgi?id=1272924 * https://bugzilla.suse.com/show_bug.cgi?id=1272925 * https://bugzilla.suse.com/show_bug.cgi?id=1272926 * https://bugzilla.suse.com/show_bug.cgi?id=1272927 * https://bugzilla.suse.com/show_bug.cgi?id=1272928 * https://bugzilla.suse.com/show_bug.cgi?id=1272930 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:36:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:36:01 -0000 Subject: SUSE-SU-2026:3506-1: critical: Security update for pcp Message-ID: <178596216147.471.11448499433967196386@dac66d42c24b> # Security update for pcp Announcement ID: SUSE-SU-2026:3506-1 Release Date: 2026-08-05T13:19:25Z Rating: critical References: * bsc#1272922 * bsc#1272923 * bsc#1272924 * bsc#1272925 * bsc#1272926 * bsc#1272927 * bsc#1272928 * bsc#1272930 Cross-References: * CVE-2026-16524 * CVE-2026-16526 * CVE-2026-16527 * CVE-2026-16529 * CVE-2026-16530 * CVE-2026-16531 CVSS scores: * CVE-2026-16524 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16524 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16527 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-16527 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-16527 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-16529 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16529 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16529 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16530 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16530 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-16530 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16531 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-16531 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-16531 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves six vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). * CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). * CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). * CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). * CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). * CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). * Command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928). * Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3506=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3506=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3506=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3506=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3506=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * pcp-debugsource-6.2.0-150400.5.15.1 * perl-PCP-MMV-6.2.0-150400.5.15.1 * libpcp_web1-6.2.0-150400.5.15.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-LogImport-6.2.0-150400.5.15.1 * pcp-devel-6.2.0-150400.5.15.1 * perl-PCP-LogSummary-6.2.0-150400.5.15.1 * libpcp_import1-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.15.1 * pcp-system-tools-6.2.0-150400.5.15.1 * libpcp_gui2-6.2.0-150400.5.15.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.15.1 * libpcp_trace2-6.2.0-150400.5.15.1 * python3-pcp-6.2.0-150400.5.15.1 * libpcp_web1-debuginfo-6.2.0-150400.5.15.1 * pcp-6.2.0-150400.5.15.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-6.2.0-150400.5.15.1 * pcp-devel-debuginfo-6.2.0-150400.5.15.1 * libpcp3-6.2.0-150400.5.15.1 * libpcp_mmv1-6.2.0-150400.5.15.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.15.1 * libpcp-devel-6.2.0-150400.5.15.1 * pcp-debuginfo-6.2.0-150400.5.15.1 * python3-pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp3-debuginfo-6.2.0-150400.5.15.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.15.1 * libpcp_import1-6.2.0-150400.5.15.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * pcp-import-iostat2pcp-6.2.0-150400.5.15.1 * pcp-doc-6.2.0-150400.5.15.1 * pcp-import-sar2pcp-6.2.0-150400.5.15.1 * pcp-conf-6.2.0-150400.5.15.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le) * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-perfevent-6.2.0-150400.5.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * pcp-debugsource-6.2.0-150400.5.15.1 * perl-PCP-MMV-6.2.0-150400.5.15.1 * libpcp_web1-6.2.0-150400.5.15.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-LogImport-6.2.0-150400.5.15.1 * pcp-devel-6.2.0-150400.5.15.1 * perl-PCP-LogSummary-6.2.0-150400.5.15.1 * libpcp_import1-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.15.1 * pcp-system-tools-6.2.0-150400.5.15.1 * libpcp_gui2-6.2.0-150400.5.15.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.15.1 * libpcp_trace2-6.2.0-150400.5.15.1 * python3-pcp-6.2.0-150400.5.15.1 * libpcp_web1-debuginfo-6.2.0-150400.5.15.1 * pcp-6.2.0-150400.5.15.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-6.2.0-150400.5.15.1 * pcp-devel-debuginfo-6.2.0-150400.5.15.1 * libpcp3-6.2.0-150400.5.15.1 * libpcp_mmv1-6.2.0-150400.5.15.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.15.1 * libpcp-devel-6.2.0-150400.5.15.1 * pcp-debuginfo-6.2.0-150400.5.15.1 * python3-pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp3-debuginfo-6.2.0-150400.5.15.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.15.1 * libpcp_import1-6.2.0-150400.5.15.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le) * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-perfevent-6.2.0-150400.5.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * pcp-import-iostat2pcp-6.2.0-150400.5.15.1 * pcp-doc-6.2.0-150400.5.15.1 * pcp-import-sar2pcp-6.2.0-150400.5.15.1 * pcp-conf-6.2.0-150400.5.15.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.15.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * pcp-pmda-cisco-6.2.0-150400.5.15.1 * perl-PCP-LogImport-6.2.0-150400.5.15.1 * pcp-pmda-gfs2-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-cifs-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-mounts-6.2.0-150400.5.15.1 * pcp-import-collectl2pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp_import1-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150400.5.15.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.15.1 * pcp-6.2.0-150400.5.15.1 * pcp-pmda-sendmail-6.2.0-150400.5.15.1 * pcp-pmda-dm-6.2.0-150400.5.15.1 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150400.5.15.1 * libpcp-devel-6.2.0-150400.5.15.1 * pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp3-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-hacluster-6.2.0-150400.5.15.1 * pcp-pmda-bind2-6.2.0-150400.5.15.1 * libpcp_import1-6.2.0-150400.5.15.1 * pcp-gui-6.2.0-150400.5.15.1 * pcp-pmda-smart-6.2.0-150400.5.15.1 * perl-PCP-MMV-6.2.0-150400.5.15.1 * pcp-pmda-smart-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-systemd-6.2.0-150400.5.15.1 * pcp-pmda-hacluster-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-weblog-debuginfo-6.2.0-150400.5.15.1 * pcp-devel-6.2.0-150400.5.15.1 * pcp-pmda-roomtemp-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-LogSummary-6.2.0-150400.5.15.1 * pcp-pmda-mounts-debuginfo-6.2.0-150400.5.15.1 * pcp-gui-debuginfo-6.2.0-150400.5.15.1 * python3-pcp-6.2.0-150400.5.15.1 * libpcp_web1-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-cifs-6.2.0-150400.5.15.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.15.1 * pcp-devel-debuginfo-6.2.0-150400.5.15.1 * libpcp3-6.2.0-150400.5.15.1 * pcp-pmda-docker-6.2.0-150400.5.15.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-shping-6.2.0-150400.5.15.1 * libpcp_web1-6.2.0-150400.5.15.1 * pcp-pmda-zimbra-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-apache-6.2.0-150400.5.15.1 * pcp-pmda-sockets-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-sockets-6.2.0-150400.5.15.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-docker-debuginfo-6.2.0-150400.5.15.1 * libpcp_gui2-6.2.0-150400.5.15.1 * pcp-system-tools-6.2.0-150400.5.15.1 * libpcp_trace2-6.2.0-150400.5.15.1 * pcp-pmda-weblog-6.2.0-150400.5.15.1 * pcp-pmda-logger-6.2.0-150400.5.15.1 * pcp-pmda-systemd-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-shping-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-summary-6.2.0-150400.5.15.1 * pcp-pmda-apache-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-sendmail-debuginfo-6.2.0-150400.5.15.1 * libpcp_mmv1-6.2.0-150400.5.15.1 * pcp-pmda-summary-debuginfo-6.2.0-150400.5.15.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.15.1 * python3-pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.15.1 * pcp-debugsource-6.2.0-150400.5.15.1 * pcp-pmda-logger-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-trace-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-bash-6.2.0-150400.5.15.1 * pcp-testsuite-6.2.0-150400.5.15.1 * pcp-pmda-bash-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-mailq-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-nvidia-gpu-6.2.0-150400.5.15.1 * pcp-pmda-mailq-6.2.0-150400.5.15.1 * pcp-testsuite-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-6.2.0-150400.5.15.1 * pcp-pmda-gfs2-6.2.0-150400.5.15.1 * pcp-pmda-trace-6.2.0-150400.5.15.1 * pcp-pmda-cisco-debuginfo-6.2.0-150400.5.15.1 * pcp-import-collectl2pcp-6.2.0-150400.5.15.1 * pcp-pmda-lustrecomm-6.2.0-150400.5.15.1 * pcp-pmda-zimbra-6.2.0-150400.5.15.1 * pcp-pmda-roomtemp-6.2.0-150400.5.15.1 * pcp-pmda-dm-debuginfo-6.2.0-150400.5.15.1 * openSUSE Leap 15.4 (noarch) * pcp-pmda-rsyslog-6.2.0-150400.5.15.1 * pcp-export-pcp2influxdb-6.2.0-150400.5.15.1 * pcp-pmda-openvswitch-6.2.0-150400.5.15.1 * pcp-export-pcp2zabbix-6.2.0-150400.5.15.1 * pcp-pmda-unbound-6.2.0-150400.5.15.1 * pcp-pmda-named-6.2.0-150400.5.15.1 * pcp-pmda-nfsclient-6.2.0-150400.5.15.1 * pcp-pmda-ds389-6.2.0-150400.5.15.1 * pcp-pmda-snmp-6.2.0-150400.5.15.1 * pcp-pmda-mysql-6.2.0-150400.5.15.1 * pcp-pmda-ds389log-6.2.0-150400.5.15.1 * pcp-pmda-news-6.2.0-150400.5.15.1 * pcp-pmda-pdns-6.2.0-150400.5.15.1 * pcp-pmda-activemq-6.2.0-150400.5.15.1 * pcp-pmda-zswap-6.2.0-150400.5.15.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.15.1 * pcp-pmda-samba-6.2.0-150400.5.15.1 * pcp-pmda-netcheck-6.2.0-150400.5.15.1 * pcp-pmda-json-6.2.0-150400.5.15.1 * pcp-pmda-redis-6.2.0-150400.5.15.1 * pcp-pmda-lmsensors-6.2.0-150400.5.15.1 * pcp-pmda-nginx-6.2.0-150400.5.15.1 * pcp-pmda-gpfs-6.2.0-150400.5.15.1 * pcp-pmda-dbping-6.2.0-150400.5.15.1 * pcp-pmda-lustre-6.2.0-150400.5.15.1 * pcp-import-iostat2pcp-6.2.0-150400.5.15.1 * pcp-pmda-gluster-6.2.0-150400.5.15.1 * pcp-pmda-netfilter-6.2.0-150400.5.15.1 * pcp-import-ganglia2pcp-6.2.0-150400.5.15.1 * pcp-pmda-rabbitmq-6.2.0-150400.5.15.1 * pcp-export-pcp2elasticsearch-6.2.0-150400.5.15.1 * pcp-pmda-openmetrics-6.2.0-150400.5.15.1 * pcp-export-pcp2json-6.2.0-150400.5.15.1 * pcp-import-sar2pcp-6.2.0-150400.5.15.1 * pcp-export-pcp2spark-6.2.0-150400.5.15.1 * pcp-conf-6.2.0-150400.5.15.1 * pcp-pmda-gpsd-6.2.0-150400.5.15.1 * pcp-pmda-haproxy-6.2.0-150400.5.15.1 * pcp-pmda-postfix-6.2.0-150400.5.15.1 * pcp-pmda-bonding-6.2.0-150400.5.15.1 * pcp-doc-6.2.0-150400.5.15.1 * pcp-pmda-nutcracker-6.2.0-150400.5.15.1 * pcp-zeroconf-6.2.0-150400.5.15.1 * pcp-pmda-elasticsearch-6.2.0-150400.5.15.1 * pcp-pmda-memcache-6.2.0-150400.5.15.1 * pcp-export-pcp2graphite-6.2.0-150400.5.15.1 * pcp-pmda-oracle-6.2.0-150400.5.15.1 * pcp-pmda-slurm-6.2.0-150400.5.15.1 * pcp-export-pcp2xml-6.2.0-150400.5.15.1 * pcp-pmda-mic-6.2.0-150400.5.15.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le x86_64) * pcp-pmda-perfevent-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-infiniband-6.2.0-150400.5.15.1 * pcp-pmda-infiniband-debuginfo-6.2.0-150400.5.15.1 * pcp-pmda-perfevent-6.2.0-150400.5.15.1 * openSUSE Leap 15.4 (x86_64) * pcp-pmda-resctrl-6.2.0-150400.5.15.1 * pcp-pmda-resctrl-debuginfo-6.2.0-150400.5.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * pcp-debugsource-6.2.0-150400.5.15.1 * perl-PCP-MMV-6.2.0-150400.5.15.1 * libpcp_web1-6.2.0-150400.5.15.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-LogImport-6.2.0-150400.5.15.1 * pcp-devel-6.2.0-150400.5.15.1 * perl-PCP-LogSummary-6.2.0-150400.5.15.1 * libpcp_import1-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.15.1 * pcp-system-tools-6.2.0-150400.5.15.1 * libpcp_gui2-6.2.0-150400.5.15.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.15.1 * libpcp_trace2-6.2.0-150400.5.15.1 * python3-pcp-6.2.0-150400.5.15.1 * libpcp_web1-debuginfo-6.2.0-150400.5.15.1 * pcp-6.2.0-150400.5.15.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-6.2.0-150400.5.15.1 * pcp-devel-debuginfo-6.2.0-150400.5.15.1 * libpcp3-6.2.0-150400.5.15.1 * libpcp_mmv1-6.2.0-150400.5.15.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.15.1 * libpcp-devel-6.2.0-150400.5.15.1 * pcp-debuginfo-6.2.0-150400.5.15.1 * python3-pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp3-debuginfo-6.2.0-150400.5.15.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.15.1 * libpcp_import1-6.2.0-150400.5.15.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * pcp-import-iostat2pcp-6.2.0-150400.5.15.1 * pcp-doc-6.2.0-150400.5.15.1 * pcp-import-sar2pcp-6.2.0-150400.5.15.1 * pcp-conf-6.2.0-150400.5.15.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * pcp-debugsource-6.2.0-150400.5.15.1 * perl-PCP-MMV-6.2.0-150400.5.15.1 * libpcp_web1-6.2.0-150400.5.15.1 * perl-PCP-LogImport-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-LogImport-6.2.0-150400.5.15.1 * pcp-devel-6.2.0-150400.5.15.1 * perl-PCP-LogSummary-6.2.0-150400.5.15.1 * libpcp_import1-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-debuginfo-6.2.0-150400.5.15.1 * pcp-system-tools-6.2.0-150400.5.15.1 * libpcp_gui2-6.2.0-150400.5.15.1 * libpcp_gui2-debuginfo-6.2.0-150400.5.15.1 * libpcp_trace2-6.2.0-150400.5.15.1 * python3-pcp-6.2.0-150400.5.15.1 * libpcp_web1-debuginfo-6.2.0-150400.5.15.1 * pcp-6.2.0-150400.5.15.1 * libpcp_trace2-debuginfo-6.2.0-150400.5.15.1 * perl-PCP-PMDA-6.2.0-150400.5.15.1 * pcp-devel-debuginfo-6.2.0-150400.5.15.1 * libpcp3-6.2.0-150400.5.15.1 * libpcp_mmv1-6.2.0-150400.5.15.1 * pcp-system-tools-debuginfo-6.2.0-150400.5.15.1 * libpcp-devel-6.2.0-150400.5.15.1 * pcp-debuginfo-6.2.0-150400.5.15.1 * python3-pcp-debuginfo-6.2.0-150400.5.15.1 * libpcp3-debuginfo-6.2.0-150400.5.15.1 * libpcp_mmv1-debuginfo-6.2.0-150400.5.15.1 * libpcp_import1-6.2.0-150400.5.15.1 * perl-PCP-MMV-debuginfo-6.2.0-150400.5.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * pcp-import-iostat2pcp-6.2.0-150400.5.15.1 * pcp-doc-6.2.0-150400.5.15.1 * pcp-import-sar2pcp-6.2.0-150400.5.15.1 * pcp-conf-6.2.0-150400.5.15.1 * pcp-import-mrtg2pcp-6.2.0-150400.5.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16524.html * https://www.suse.com/security/cve/CVE-2026-16526.html * https://www.suse.com/security/cve/CVE-2026-16527.html * https://www.suse.com/security/cve/CVE-2026-16529.html * https://www.suse.com/security/cve/CVE-2026-16530.html * https://www.suse.com/security/cve/CVE-2026-16531.html * https://bugzilla.suse.com/show_bug.cgi?id=1272922 * https://bugzilla.suse.com/show_bug.cgi?id=1272923 * https://bugzilla.suse.com/show_bug.cgi?id=1272924 * https://bugzilla.suse.com/show_bug.cgi?id=1272925 * https://bugzilla.suse.com/show_bug.cgi?id=1272926 * https://bugzilla.suse.com/show_bug.cgi?id=1272927 * https://bugzilla.suse.com/show_bug.cgi?id=1272928 * https://bugzilla.suse.com/show_bug.cgi?id=1272930 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:37:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:37:07 -0000 Subject: SUSE-SU-2026:3505-1: critical: Security update for pcp Message-ID: <178596222789.471.13854764110029672676@dac66d42c24b> # Security update for pcp Announcement ID: SUSE-SU-2026:3505-1 Release Date: 2026-08-05T13:18:41Z Rating: critical References: * bsc#1272922 * bsc#1272923 * bsc#1272924 * bsc#1272925 * bsc#1272926 * bsc#1272927 * bsc#1272928 * bsc#1272930 Cross-References: * CVE-2026-16524 * CVE-2026-16526 * CVE-2026-16527 * CVE-2026-16529 * CVE-2026-16530 * CVE-2026-16531 CVSS scores: * CVE-2026-16524 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16524 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16524 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-16526 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16526 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16527 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-16527 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-16527 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-16529 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16529 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16529 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16530 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16530 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-16530 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16531 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-16531 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-16531 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities and has two security fixes can now be installed. ## Description: This update for pcp fixes the following issues: * CVE-2026-16524: command injection in `linux_sockets` PMDA via `network.persocket.filter` (bsc#1272922). * CVE-2026-16526: pmdaroot privilege escalation via `FD_CLOEXEC` fd inheritance and missing peer credentials (bsc#1272923). * CVE-2026-16527: missing authentication flags in pmproxy REST API (bsc#1272924). * CVE-2026-16529: integer overflow in `__pmGetPDU` leads to permanent DoS (bsc#1272925). * CVE-2026-16530: multiple OOB reads in libpcp record and PDU decoders (bsc#1272926). * CVE-2026-16531: path traversal via hostname in pmproxy logger servlet (bsc#1272927). * Command injection in `pmieconf` `write_pmiefile` via `$HOME` and `-f` (bsc#1272928). * Command injection in `pmlogcp/pmlogmv` `do_link` via unsanitised filenames (bsc#1272930). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3505=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3505=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3505=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3505=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3505=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * pcp-system-tools-6.2.0-150500.8.9.1 * pcp-system-tools-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-LogImport-6.2.0-150500.8.9.1 * perl-PCP-LogSummary-6.2.0-150500.8.9.1 * perl-PCP-MMV-6.2.0-150500.8.9.1 * libpcp3-debuginfo-6.2.0-150500.8.9.1 * pcp-devel-6.2.0-150500.8.9.1 * python3-pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_import1-6.2.0-150500.8.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150500.8.9.1 * libpcp3-6.2.0-150500.8.9.1 * libpcp_import1-debuginfo-6.2.0-150500.8.9.1 * libpcp_web1-6.2.0-150500.8.9.1 * pcp-devel-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-PMDA-6.2.0-150500.8.9.1 * libpcp_gui2-6.2.0-150500.8.9.1 * python3-pcp-6.2.0-150500.8.9.1 * libpcp_trace2-debuginfo-6.2.0-150500.8.9.1 * libpcp_gui2-debuginfo-6.2.0-150500.8.9.1 * pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_mmv1-debuginfo-6.2.0-150500.8.9.1 * libpcp_trace2-6.2.0-150500.8.9.1 * libpcp_web1-debuginfo-6.2.0-150500.8.9.1 * libpcp-devel-6.2.0-150500.8.9.1 * pcp-debugsource-6.2.0-150500.8.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150500.8.9.1 * pcp-6.2.0-150500.8.9.1 * libpcp_mmv1-6.2.0-150500.8.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le) * pcp-pmda-perfevent-6.2.0-150500.8.9.1 * pcp-pmda-perfevent-debuginfo-6.2.0-150500.8.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * pcp-import-sar2pcp-6.2.0-150500.8.9.1 * pcp-conf-6.2.0-150500.8.9.1 * pcp-import-iostat2pcp-6.2.0-150500.8.9.1 * pcp-doc-6.2.0-150500.8.9.1 * pcp-import-mrtg2pcp-6.2.0-150500.8.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le) * pcp-pmda-perfevent-6.2.0-150500.8.9.1 * pcp-pmda-perfevent-debuginfo-6.2.0-150500.8.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * pcp-system-tools-6.2.0-150500.8.9.1 * perl-PCP-LogSummary-6.2.0-150500.8.9.1 * pcp-system-tools-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-LogImport-6.2.0-150500.8.9.1 * perl-PCP-MMV-6.2.0-150500.8.9.1 * libpcp3-debuginfo-6.2.0-150500.8.9.1 * pcp-devel-6.2.0-150500.8.9.1 * python3-pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_import1-6.2.0-150500.8.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150500.8.9.1 * libpcp3-6.2.0-150500.8.9.1 * libpcp_import1-debuginfo-6.2.0-150500.8.9.1 * libpcp_web1-6.2.0-150500.8.9.1 * pcp-devel-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-PMDA-6.2.0-150500.8.9.1 * libpcp_gui2-6.2.0-150500.8.9.1 * python3-pcp-6.2.0-150500.8.9.1 * libpcp_trace2-debuginfo-6.2.0-150500.8.9.1 * libpcp_gui2-debuginfo-6.2.0-150500.8.9.1 * pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_mmv1-debuginfo-6.2.0-150500.8.9.1 * libpcp_trace2-6.2.0-150500.8.9.1 * libpcp_web1-debuginfo-6.2.0-150500.8.9.1 * libpcp-devel-6.2.0-150500.8.9.1 * pcp-debugsource-6.2.0-150500.8.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150500.8.9.1 * pcp-6.2.0-150500.8.9.1 * libpcp_mmv1-6.2.0-150500.8.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * pcp-import-sar2pcp-6.2.0-150500.8.9.1 * pcp-conf-6.2.0-150500.8.9.1 * pcp-import-iostat2pcp-6.2.0-150500.8.9.1 * pcp-doc-6.2.0-150500.8.9.1 * pcp-import-mrtg2pcp-6.2.0-150500.8.9.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * pcp-system-tools-debuginfo-6.2.0-150500.8.9.1 * libpcp3-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-logger-6.2.0-150500.8.9.1 * libpcp_import1-6.2.0-150500.8.9.1 * pcp-pmda-systemd-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-summary-debuginfo-6.2.0-150500.8.9.1 * libpcp_web1-6.2.0-150500.8.9.1 * pcp-pmda-sendmail-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-gfs2-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-roomtemp-6.2.0-150500.8.9.1 * libpcp_gui2-6.2.0-150500.8.9.1 * pcp-pmda-sockets-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-trace-6.2.0-150500.8.9.1 * libpcp-devel-6.2.0-150500.8.9.1 * pcp-debugsource-6.2.0-150500.8.9.1 * pcp-pmda-systemd-6.2.0-150500.8.9.1 * pcp-pmda-gfs2-6.2.0-150500.8.9.1 * pcp-6.2.0-150500.8.9.1 * libpcp_web1-debuginfo-6.2.0-150500.8.9.1 * libpcp_mmv1-6.2.0-150500.8.9.1 * perl-PCP-LogImport-6.2.0-150500.8.9.1 * perl-PCP-MMV-6.2.0-150500.8.9.1 * python3-pcp-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-zimbra-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150500.8.9.1 * pcp-gui-6.2.0-150500.8.9.1 * pcp-import-collectl2pcp-6.2.0-150500.8.9.1 * pcp-pmda-docker-debuginfo-6.2.0-150500.8.9.1 * libpcp_import1-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-mounts-6.2.0-150500.8.9.1 * pcp-pmda-trace-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-apache-6.2.0-150500.8.9.1 * pcp-pmda-nvidia-gpu-6.2.0-150500.8.9.1 * pcp-pmda-apache-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-cifs-6.2.0-150500.8.9.1 * pcp-pmda-dm-6.2.0-150500.8.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-PMDA-6.2.0-150500.8.9.1 * libpcp_trace2-debuginfo-6.2.0-150500.8.9.1 * pcp-gui-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150500.8.9.1 * pcp-import-collectl2pcp-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-lustrecomm-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-hacluster-6.2.0-150500.8.9.1 * pcp-pmda-roomtemp-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-mailq-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-lustrecomm-6.2.0-150500.8.9.1 * pcp-devel-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-cifs-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-nvidia-gpu-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-docker-6.2.0-150500.8.9.1 * python3-pcp-6.2.0-150500.8.9.1 * pcp-pmda-sockets-6.2.0-150500.8.9.1 * pcp-pmda-sendmail-6.2.0-150500.8.9.1 * pcp-pmda-logger-debuginfo-6.2.0-150500.8.9.1 * pcp-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-weblog-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-weblog-6.2.0-150500.8.9.1 * libpcp_trace2-6.2.0-150500.8.9.1 * pcp-system-tools-6.2.0-150500.8.9.1 * pcp-pmda-smart-6.2.0-150500.8.9.1 * perl-PCP-LogSummary-6.2.0-150500.8.9.1 * pcp-pmda-bash-debuginfo-6.2.0-150500.8.9.1 * pcp-testsuite-6.2.0-150500.8.9.1 * pcp-devel-6.2.0-150500.8.9.1 * pcp-pmda-bind2-6.2.0-150500.8.9.1 * libpcp3-6.2.0-150500.8.9.1 * pcp-pmda-smart-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-summary-6.2.0-150500.8.9.1 * pcp-pmda-hacluster-debuginfo-6.2.0-150500.8.9.1 * pcp-testsuite-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-dm-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-shping-6.2.0-150500.8.9.1 * pcp-pmda-cisco-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-zimbra-6.2.0-150500.8.9.1 * pcp-pmda-mailq-6.2.0-150500.8.9.1 * pcp-pmda-mounts-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-bash-6.2.0-150500.8.9.1 * libpcp_gui2-debuginfo-6.2.0-150500.8.9.1 * libpcp_mmv1-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-cisco-6.2.0-150500.8.9.1 * pcp-pmda-shping-debuginfo-6.2.0-150500.8.9.1 * openSUSE Leap 15.5 (noarch) * pcp-export-pcp2json-6.2.0-150500.8.9.1 * pcp-import-sar2pcp-6.2.0-150500.8.9.1 * pcp-pmda-gluster-6.2.0-150500.8.9.1 * pcp-pmda-netcheck-6.2.0-150500.8.9.1 * pcp-pmda-postfix-6.2.0-150500.8.9.1 * pcp-pmda-unbound-6.2.0-150500.8.9.1 * pcp-pmda-dbping-6.2.0-150500.8.9.1 * pcp-pmda-ds389log-6.2.0-150500.8.9.1 * pcp-pmda-nutcracker-6.2.0-150500.8.9.1 * pcp-pmda-gpfs-6.2.0-150500.8.9.1 * pcp-pmda-bonding-6.2.0-150500.8.9.1 * pcp-pmda-json-6.2.0-150500.8.9.1 * pcp-pmda-elasticsearch-6.2.0-150500.8.9.1 * pcp-pmda-openvswitch-6.2.0-150500.8.9.1 * pcp-pmda-nginx-6.2.0-150500.8.9.1 * pcp-import-ganglia2pcp-6.2.0-150500.8.9.1 * pcp-export-pcp2influxdb-6.2.0-150500.8.9.1 * pcp-pmda-mysql-6.2.0-150500.8.9.1 * pcp-pmda-snmp-6.2.0-150500.8.9.1 * pcp-import-iostat2pcp-6.2.0-150500.8.9.1 * pcp-pmda-haproxy-6.2.0-150500.8.9.1 * pcp-pmda-samba-6.2.0-150500.8.9.1 * pcp-pmda-activemq-6.2.0-150500.8.9.1 * pcp-import-mrtg2pcp-6.2.0-150500.8.9.1 * pcp-zeroconf-6.2.0-150500.8.9.1 * pcp-pmda-nfsclient-6.2.0-150500.8.9.1 * pcp-export-pcp2spark-6.2.0-150500.8.9.1 * pcp-pmda-lmsensors-6.2.0-150500.8.9.1 * pcp-pmda-redis-6.2.0-150500.8.9.1 * pcp-doc-6.2.0-150500.8.9.1 * pcp-pmda-zswap-6.2.0-150500.8.9.1 * pcp-pmda-pdns-6.2.0-150500.8.9.1 * pcp-pmda-rabbitmq-6.2.0-150500.8.9.1 * pcp-pmda-gpsd-6.2.0-150500.8.9.1 * pcp-pmda-openmetrics-6.2.0-150500.8.9.1 * pcp-pmda-mic-6.2.0-150500.8.9.1 * pcp-export-pcp2xml-6.2.0-150500.8.9.1 * pcp-export-pcp2elasticsearch-6.2.0-150500.8.9.1 * pcp-conf-6.2.0-150500.8.9.1 * pcp-pmda-named-6.2.0-150500.8.9.1 * pcp-pmda-rsyslog-6.2.0-150500.8.9.1 * pcp-pmda-netfilter-6.2.0-150500.8.9.1 * pcp-pmda-lustre-6.2.0-150500.8.9.1 * pcp-export-pcp2graphite-6.2.0-150500.8.9.1 * pcp-pmda-memcache-6.2.0-150500.8.9.1 * pcp-pmda-ds389-6.2.0-150500.8.9.1 * pcp-export-pcp2zabbix-6.2.0-150500.8.9.1 * pcp-pmda-news-6.2.0-150500.8.9.1 * pcp-pmda-slurm-6.2.0-150500.8.9.1 * pcp-pmda-oracle-6.2.0-150500.8.9.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le x86_64) * pcp-pmda-perfevent-6.2.0-150500.8.9.1 * pcp-pmda-perfevent-debuginfo-6.2.0-150500.8.9.1 * pcp-pmda-infiniband-6.2.0-150500.8.9.1 * pcp-pmda-infiniband-debuginfo-6.2.0-150500.8.9.1 * openSUSE Leap 15.5 (x86_64) * pcp-pmda-resctrl-6.2.0-150500.8.9.1 * pcp-pmda-resctrl-debuginfo-6.2.0-150500.8.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * pcp-system-tools-6.2.0-150500.8.9.1 * perl-PCP-LogImport-6.2.0-150500.8.9.1 * perl-PCP-LogSummary-6.2.0-150500.8.9.1 * pcp-system-tools-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-MMV-6.2.0-150500.8.9.1 * libpcp3-debuginfo-6.2.0-150500.8.9.1 * pcp-devel-6.2.0-150500.8.9.1 * python3-pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_import1-6.2.0-150500.8.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150500.8.9.1 * libpcp3-6.2.0-150500.8.9.1 * libpcp_import1-debuginfo-6.2.0-150500.8.9.1 * libpcp_web1-6.2.0-150500.8.9.1 * pcp-devel-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-PMDA-6.2.0-150500.8.9.1 * libpcp_gui2-6.2.0-150500.8.9.1 * python3-pcp-6.2.0-150500.8.9.1 * libpcp_trace2-debuginfo-6.2.0-150500.8.9.1 * libpcp_gui2-debuginfo-6.2.0-150500.8.9.1 * pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_mmv1-debuginfo-6.2.0-150500.8.9.1 * libpcp_trace2-6.2.0-150500.8.9.1 * libpcp_web1-debuginfo-6.2.0-150500.8.9.1 * libpcp-devel-6.2.0-150500.8.9.1 * pcp-debugsource-6.2.0-150500.8.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150500.8.9.1 * pcp-6.2.0-150500.8.9.1 * libpcp_mmv1-6.2.0-150500.8.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * pcp-import-sar2pcp-6.2.0-150500.8.9.1 * pcp-conf-6.2.0-150500.8.9.1 * pcp-import-iostat2pcp-6.2.0-150500.8.9.1 * pcp-doc-6.2.0-150500.8.9.1 * pcp-import-mrtg2pcp-6.2.0-150500.8.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * pcp-system-tools-6.2.0-150500.8.9.1 * perl-PCP-LogSummary-6.2.0-150500.8.9.1 * pcp-system-tools-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-LogImport-6.2.0-150500.8.9.1 * perl-PCP-MMV-6.2.0-150500.8.9.1 * libpcp3-debuginfo-6.2.0-150500.8.9.1 * pcp-devel-6.2.0-150500.8.9.1 * python3-pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_import1-6.2.0-150500.8.9.1 * perl-PCP-LogImport-debuginfo-6.2.0-150500.8.9.1 * libpcp3-6.2.0-150500.8.9.1 * libpcp_import1-debuginfo-6.2.0-150500.8.9.1 * libpcp_web1-6.2.0-150500.8.9.1 * pcp-devel-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-MMV-debuginfo-6.2.0-150500.8.9.1 * perl-PCP-PMDA-6.2.0-150500.8.9.1 * libpcp_gui2-6.2.0-150500.8.9.1 * python3-pcp-6.2.0-150500.8.9.1 * libpcp_trace2-debuginfo-6.2.0-150500.8.9.1 * libpcp_gui2-debuginfo-6.2.0-150500.8.9.1 * pcp-debuginfo-6.2.0-150500.8.9.1 * libpcp_mmv1-debuginfo-6.2.0-150500.8.9.1 * libpcp_trace2-6.2.0-150500.8.9.1 * libpcp_web1-debuginfo-6.2.0-150500.8.9.1 * libpcp-devel-6.2.0-150500.8.9.1 * pcp-debugsource-6.2.0-150500.8.9.1 * perl-PCP-PMDA-debuginfo-6.2.0-150500.8.9.1 * pcp-6.2.0-150500.8.9.1 * libpcp_mmv1-6.2.0-150500.8.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * pcp-import-sar2pcp-6.2.0-150500.8.9.1 * pcp-conf-6.2.0-150500.8.9.1 * pcp-import-iostat2pcp-6.2.0-150500.8.9.1 * pcp-doc-6.2.0-150500.8.9.1 * pcp-import-mrtg2pcp-6.2.0-150500.8.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16524.html * https://www.suse.com/security/cve/CVE-2026-16526.html * https://www.suse.com/security/cve/CVE-2026-16527.html * https://www.suse.com/security/cve/CVE-2026-16529.html * https://www.suse.com/security/cve/CVE-2026-16530.html * https://www.suse.com/security/cve/CVE-2026-16531.html * https://bugzilla.suse.com/show_bug.cgi?id=1272922 * https://bugzilla.suse.com/show_bug.cgi?id=1272923 * https://bugzilla.suse.com/show_bug.cgi?id=1272924 * https://bugzilla.suse.com/show_bug.cgi?id=1272925 * https://bugzilla.suse.com/show_bug.cgi?id=1272926 * https://bugzilla.suse.com/show_bug.cgi?id=1272927 * https://bugzilla.suse.com/show_bug.cgi?id=1272928 * https://bugzilla.suse.com/show_bug.cgi?id=1272930 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:38:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:38:03 -0000 Subject: SUSE-SU-2026:3504-1: moderate: Security update for containerd Message-ID: <178596228382.471.4359044866425137474@dac66d42c24b> # Security update for containerd Announcement ID: SUSE-SU-2026:3504-1 Release Date: 2026-08-05T12:50:06Z Rating: moderate References: * bsc#1262266 Cross-References: * CVE-2026-35469 CVSS scores: * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for containerd fixes the following issues: * CVE-2026-35469: github.com/moby/spdystream: memory amplification in SPDY frame parsing leads to denial of service (bsc#1262266). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3504=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * containerd-ctr-1.7.29-16.113.1 * containerd-1.7.29-16.113.1 * containerd-devel-1.7.29-16.113.1 ## References: * https://www.suse.com/security/cve/CVE-2026-35469.html * https://bugzilla.suse.com/show_bug.cgi?id=1262266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:38:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:38:47 -0000 Subject: SUSE-SU-2026:3503-1: critical: Security update for python-Django Message-ID: <178596232726.471.6570352505060538078@dac66d42c24b> # Security update for python-Django Announcement ID: SUSE-SU-2026:3503-1 Release Date: 2026-08-05T12:49:57Z Rating: critical References: * bsc#1272997 * bsc#1272998 * bsc#1272999 * bsc#1273000 Cross-References: * CVE-2026-15307 * CVE-2026-15337 * CVE-2026-15830 * CVE-2026-15920 CVSS scores: * CVE-2026-15307 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:N * CVE-2026-15307 ( SUSE ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-15307 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15307 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15337 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15337 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15337 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-15830 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15830 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15830 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15830 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-15920 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-15920 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-15920 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15920 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-Django fixes the following issues: * CVE-2026-15307: server-side file-write and request forgery via spatial lookups (bsc#1272997). * CVE-2026-15337: potential denial-of-service vulnerability in `check_for_language()` (bsc#1272998). * CVE-2026-15830: potential denial-of-service vulnerability via nested geometry collections (bsc#1272999). * CVE-2026-15920: potential cross-site scripting via `URLField` values in the admin (bsc#1273000). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3503=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3503=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python311-Django-4.2.11-150600.3.65.1 * openSUSE Leap 15.6 (noarch) * python311-Django-4.2.11-150600.3.65.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15307.html * https://www.suse.com/security/cve/CVE-2026-15337.html * https://www.suse.com/security/cve/CVE-2026-15830.html * https://www.suse.com/security/cve/CVE-2026-15920.html * https://bugzilla.suse.com/show_bug.cgi?id=1272997 * https://bugzilla.suse.com/show_bug.cgi?id=1272998 * https://bugzilla.suse.com/show_bug.cgi?id=1272999 * https://bugzilla.suse.com/show_bug.cgi?id=1273000 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:39:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:39:43 -0000 Subject: SUSE-SU-2026:3502-1: important: Security update for openssl-3 Message-ID: <178596238326.471.11950848124144455111@dac66d42c24b> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3502-1 Release Date: 2026-08-05T12:45:16Z Rating: important References: * bsc#1271712 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has one security fix can now be installed. ## Description: This update for openssl-3 fixes the following issue * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3502=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3502=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3502=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3502=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3502=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-devel-3.0.8-150500.5.72.1 * openssl-3-debugsource-3.0.8-150500.5.72.1 * openssl-3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-3.0.8-150500.5.72.1 * openssl-3-3.0.8-150500.5.72.1 * openSUSE Leap 15.5 (noarch) * openssl-3-doc-3.0.8-150500.5.72.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libopenssl-3-devel-64bit-3.0.8-150500.5.72.1 * libopenssl3-64bit-3.0.8-150500.5.72.1 * libopenssl3-64bit-debuginfo-3.0.8-150500.5.72.1 * openSUSE Leap 15.5 (x86_64) * libopenssl-3-devel-32bit-3.0.8-150500.5.72.1 * libopenssl3-32bit-3.0.8-150500.5.72.1 * libopenssl3-32bit-debuginfo-3.0.8-150500.5.72.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libopenssl-3-devel-3.0.8-150500.5.72.1 * openssl-3-debugsource-3.0.8-150500.5.72.1 * openssl-3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-3.0.8-150500.5.72.1 * openssl-3-3.0.8-150500.5.72.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libopenssl-3-devel-3.0.8-150500.5.72.1 * openssl-3-debugsource-3.0.8-150500.5.72.1 * openssl-3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-3.0.8-150500.5.72.1 * openssl-3-3.0.8-150500.5.72.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.0.8-150500.5.72.1 * openssl-3-debugsource-3.0.8-150500.5.72.1 * openssl-3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-3.0.8-150500.5.72.1 * openssl-3-3.0.8-150500.5.72.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libopenssl-3-devel-3.0.8-150500.5.72.1 * openssl-3-debugsource-3.0.8-150500.5.72.1 * openssl-3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-debuginfo-3.0.8-150500.5.72.1 * libopenssl3-3.0.8-150500.5.72.1 * openssl-3-3.0.8-150500.5.72.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Aug 5 20:42:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 05 Aug 2026 20:42:00 -0000 Subject: SUSE-SU-2026:3501-1: important: Security update for wireshark Message-ID: <178596252083.471.8963354240988189253@dac66d42c24b> # Security update for wireshark Announcement ID: SUSE-SU-2026:3501-1 Release Date: 2026-08-05T12:41:59Z Rating: important References: * bsc#1263725 * bsc#1263726 * bsc#1263727 * bsc#1263728 * bsc#1263729 * bsc#1263730 * bsc#1263731 * bsc#1263732 * bsc#1263733 * bsc#1263734 * bsc#1263735 * bsc#1263736 * bsc#1263737 * bsc#1263738 * bsc#1263739 * bsc#1263740 * bsc#1263741 * bsc#1263742 * bsc#1263743 * bsc#1263744 * bsc#1263745 * bsc#1263746 * bsc#1263747 * bsc#1263748 * bsc#1263749 * bsc#1263750 * bsc#1263751 * bsc#1263752 * bsc#1263753 * bsc#1263754 * bsc#1263755 * bsc#1263756 * bsc#1263757 * bsc#1263758 * bsc#1263759 * bsc#1263760 * bsc#1263761 * bsc#1263762 * bsc#1263765 * bsc#1263766 * bsc#1263767 * bsc#1263809 * bsc#1263810 * bsc#1266670 * bsc#1271133 * bsc#1271134 * bsc#1271135 * bsc#1271136 * bsc#1271137 * bsc#1271138 * bsc#1271139 * bsc#1271140 * bsc#1271141 * bsc#1271142 * bsc#1271143 * bsc#1271144 Cross-References: * CVE-2026-15163 * CVE-2026-15164 * CVE-2026-15165 * CVE-2026-15166 * CVE-2026-15167 * CVE-2026-15168 * CVE-2026-15169 * CVE-2026-15170 * CVE-2026-15171 * CVE-2026-15172 * CVE-2026-15173 * CVE-2026-15174 * CVE-2026-5299 * CVE-2026-5401 * CVE-2026-5402 * CVE-2026-5403 * CVE-2026-5404 * CVE-2026-5405 * CVE-2026-5406 * CVE-2026-5407 * CVE-2026-5408 * CVE-2026-5409 * CVE-2026-5653 * CVE-2026-5654 * CVE-2026-5655 * CVE-2026-5656 * CVE-2026-5657 * CVE-2026-6519 * CVE-2026-6520 * CVE-2026-6521 * CVE-2026-6522 * CVE-2026-6523 * CVE-2026-6524 * CVE-2026-6525 * CVE-2026-6526 * CVE-2026-6527 * CVE-2026-6528 * CVE-2026-6529 * CVE-2026-6530 * CVE-2026-6531 * CVE-2026-6532 * CVE-2026-6533 * CVE-2026-6534 * CVE-2026-6535 * CVE-2026-6536 * CVE-2026-6537 * CVE-2026-6538 * CVE-2026-6867 * CVE-2026-6868 * CVE-2026-6869 * CVE-2026-6870 * CVE-2026-7375 * CVE-2026-7376 * CVE-2026-7378 * CVE-2026-7379 * CVE-2026-9759 CVSS scores: * CVE-2026-15163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15165 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15165 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15165 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15167 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15168 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15168 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15168 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15170 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15170 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15173 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15173 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15173 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5299 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5401 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5402 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5402 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5402 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5403 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5403 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5404 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5404 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5404 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5405 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5405 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5405 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5406 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5407 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5408 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5408 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5654 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5654 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5654 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5655 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5656 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-5656 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5656 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5656 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5657 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5657 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5657 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6519 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6519 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6519 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6520 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6522 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6523 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6524 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6525 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6525 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6526 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6526 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6527 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6528 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6528 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6529 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6530 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6530 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6532 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6532 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6533 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6533 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6534 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6534 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6535 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6535 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6536 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6537 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6537 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6538 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6867 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6867 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6868 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6868 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6869 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6869 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6870 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7375 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7375 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7376 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7378 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7379 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9759 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9759 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 56 vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues: Update to version 4.6.7: * CVE-2026-5299: ICMPv6 dissector crash (bsc#1263757). * CVE-2026-5401: AFP dissector crash (bsc#1263756). * CVE-2026-5402: TLS dissector crash and possible code execution (bsc#1263755). * CVE-2026-5403: SBC audio codec crash (bsc#1263765). * CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766). * CVE-2026-5405: RDP dissector crash (bsc#1263767). * CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754). * CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753). * CVE-2026-5408: BT-DHT dissector crash (bsc#1263752). * CVE-2026-5409: Monero dissector crash (bsc#1263751). * CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750). * CVE-2026-5654: AMR-NB audio codec crash (bsc#1263749). * CVE-2026-5655: SDP dissector crash (bsc#1263748). * CVE-2026-5656: Profile import crash and possible code execution (bsc#1263809). * CVE-2026-5657: iLBC audio codec crash (bsc#1263747). * CVE-2026-6519: MBIM protocol dissector infinite loop (bsc#1263746). * CVE-2026-6520: OpenFlow v6 protocol dissector infinite loop (bsc#1263745). * CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744). * CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743). * CVE-2026-6523: GNW protocol dissector infinite loop (bsc#1263742). * CVE-2026-6524: MySQL protocol dissector crash (bsc#1263741). * CVE-2026-6525: IEEE 802.11 protocol dissector crash (bsc#1263810). * CVE-2026-6526: RTSP protocol dissector crash (bsc#1263740). * CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739). * CVE-2026-6528: TLS protocol dissector infinite loop (bsc#1263738). * CVE-2026-6529: iLBC audio codec crash (bsc#1263737). * CVE-2026-6530: DCP-ETSI protocol dissector crash (bsc#1263736). * CVE-2026-6531: SANE protocol dissector infinite loop (bsc#1263735). * CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734). * CVE-2026-6533: Dissection engine LZ77 decompression crash (bsc#1263733). * CVE-2026-6534: USB HID dissector infinite loop (bsc#1263732). * CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731). * CVE-2026-6536: DLMS/COSEM dissector infinite loop (bsc#1263730). * CVE-2026-6537: ZigBee dissector crash (bsc#1263729). * CVE-2026-6538: BEEP dissector crash (bsc#1263728). * CVE-2026-6867: SMB2 protocol dissector crash (bsc#1263727). * CVE-2026-6868: HTTP protocol dissector crash (bsc#1263762). * CVE-2026-6869: WebSocket protocol dissector crash (bsc#1263726). * CVE-2026-6870: GSM RP protocol dissector crash (bsc#1263725). * CVE-2026-7375: UDS protocol dissector infinite loop (bsc#1263761). * CVE-2026-7376: Sharkd utility crash (bsc#1263760). * CVE-2026-7378: Sharkd utility crash (bsc#1263759). * CVE-2026-7379: Sharkd utility memory leak (bsc#1263758). * CVE-2026-9759: ROHC protocol dissector crash (bsc#1266670). * CVE-2026-15163: Denial of Service via multiple protocol dissector infinite loops (bsc#1271133). * CVE-2026-15164: Denial of Service vulnerability in ciscodump (bsc#1271134). * CVE-2026-15165: Denial of Service via TLS ECH decryptor crash (bsc#1271135). * CVE-2026-15166: Denial of Service via IEEE 802.11 protocol dissector crash (bsc#1271136). * CVE-2026-15167: Denial of Service via DBS Etherwatch file parser crash (bsc#1271137). * CVE-2026-15168: BLF file parser allows possible information disclosure (bsc#1271138). * CVE-2026-15169: Denial of Service via UMTS FP protocol dissector crash (bsc#1271139). * CVE-2026-15170: Denial of service via Z39.50 protocol dissector crash (bsc#1271140). * CVE-2026-15171: Denial of service via SSH protocol dissector crash (bsc#1271141). * CVE-2026-15172: Denial of service via FMP/NOTIFY protocol dissector crash (bsc#1271142). * CVE-2026-15173: Denial of Service via pcapng file parser crash (bsc#1271143). * CVE-2026-15174: Denial of Service via Catapult DCT2000 protocol dissector crash (bsc#1271144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3501=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3501=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libwiretap16-debuginfo-4.6.7-150700.21.11.1 * libwireshark19-4.6.7-150700.21.11.1 * wireshark-debugsource-4.6.7-150700.21.11.1 * libwsutil17-debuginfo-4.6.7-150700.21.11.1 * libwsutil17-4.6.7-150700.21.11.1 * libwiretap16-4.6.7-150700.21.11.1 * libwireshark19-debuginfo-4.6.7-150700.21.11.1 * wireshark-debuginfo-4.6.7-150700.21.11.1 * wireshark-4.6.7-150700.21.11.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wireshark-ui-qt-4.6.7-150700.21.11.1 * wireshark-ui-qt-debuginfo-4.6.7-150700.21.11.1 * wireshark-devel-4.6.7-150700.21.11.1 * wireshark-debugsource-4.6.7-150700.21.11.1 * wireshark-debuginfo-4.6.7-150700.21.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15163.html * https://www.suse.com/security/cve/CVE-2026-15164.html * https://www.suse.com/security/cve/CVE-2026-15165.html * https://www.suse.com/security/cve/CVE-2026-15166.html * https://www.suse.com/security/cve/CVE-2026-15167.html * https://www.suse.com/security/cve/CVE-2026-15168.html * https://www.suse.com/security/cve/CVE-2026-15169.html * https://www.suse.com/security/cve/CVE-2026-15170.html * https://www.suse.com/security/cve/CVE-2026-15171.html * https://www.suse.com/security/cve/CVE-2026-15172.html * https://www.suse.com/security/cve/CVE-2026-15173.html * https://www.suse.com/security/cve/CVE-2026-15174.html * https://www.suse.com/security/cve/CVE-2026-5299.html * https://www.suse.com/security/cve/CVE-2026-5401.html * https://www.suse.com/security/cve/CVE-2026-5402.html * https://www.suse.com/security/cve/CVE-2026-5403.html * https://www.suse.com/security/cve/CVE-2026-5404.html * https://www.suse.com/security/cve/CVE-2026-5405.html * https://www.suse.com/security/cve/CVE-2026-5406.html * https://www.suse.com/security/cve/CVE-2026-5407.html * https://www.suse.com/security/cve/CVE-2026-5408.html * https://www.suse.com/security/cve/CVE-2026-5409.html * https://www.suse.com/security/cve/CVE-2026-5653.html * https://www.suse.com/security/cve/CVE-2026-5654.html * https://www.suse.com/security/cve/CVE-2026-5655.html * https://www.suse.com/security/cve/CVE-2026-5656.html * https://www.suse.com/security/cve/CVE-2026-5657.html * https://www.suse.com/security/cve/CVE-2026-6519.html * https://www.suse.com/security/cve/CVE-2026-6520.html * https://www.suse.com/security/cve/CVE-2026-6521.html * https://www.suse.com/security/cve/CVE-2026-6522.html * https://www.suse.com/security/cve/CVE-2026-6523.html * https://www.suse.com/security/cve/CVE-2026-6524.html * https://www.suse.com/security/cve/CVE-2026-6525.html * https://www.suse.com/security/cve/CVE-2026-6526.html * https://www.suse.com/security/cve/CVE-2026-6527.html * https://www.suse.com/security/cve/CVE-2026-6528.html * https://www.suse.com/security/cve/CVE-2026-6529.html * https://www.suse.com/security/cve/CVE-2026-6530.html * https://www.suse.com/security/cve/CVE-2026-6531.html * https://www.suse.com/security/cve/CVE-2026-6532.html * https://www.suse.com/security/cve/CVE-2026-6533.html * https://www.suse.com/security/cve/CVE-2026-6534.html * https://www.suse.com/security/cve/CVE-2026-6535.html * https://www.suse.com/security/cve/CVE-2026-6536.html * https://www.suse.com/security/cve/CVE-2026-6537.html * https://www.suse.com/security/cve/CVE-2026-6538.html * https://www.suse.com/security/cve/CVE-2026-6867.html * https://www.suse.com/security/cve/CVE-2026-6868.html * https://www.suse.com/security/cve/CVE-2026-6869.html * https://www.suse.com/security/cve/CVE-2026-6870.html * https://www.suse.com/security/cve/CVE-2026-7375.html * https://www.suse.com/security/cve/CVE-2026-7376.html * https://www.suse.com/security/cve/CVE-2026-7378.html * https://www.suse.com/security/cve/CVE-2026-7379.html * https://www.suse.com/security/cve/CVE-2026-9759.html * https://bugzilla.suse.com/show_bug.cgi?id=1263725 * https://bugzilla.suse.com/show_bug.cgi?id=1263726 * https://bugzilla.suse.com/show_bug.cgi?id=1263727 * https://bugzilla.suse.com/show_bug.cgi?id=1263728 * https://bugzilla.suse.com/show_bug.cgi?id=1263729 * https://bugzilla.suse.com/show_bug.cgi?id=1263730 * https://bugzilla.suse.com/show_bug.cgi?id=1263731 * https://bugzilla.suse.com/show_bug.cgi?id=1263732 * https://bugzilla.suse.com/show_bug.cgi?id=1263733 * https://bugzilla.suse.com/show_bug.cgi?id=1263734 * https://bugzilla.suse.com/show_bug.cgi?id=1263735 * https://bugzilla.suse.com/show_bug.cgi?id=1263736 * https://bugzilla.suse.com/show_bug.cgi?id=1263737 * https://bugzilla.suse.com/show_bug.cgi?id=1263738 * https://bugzilla.suse.com/show_bug.cgi?id=1263739 * https://bugzilla.suse.com/show_bug.cgi?id=1263740 * https://bugzilla.suse.com/show_bug.cgi?id=1263741 * https://bugzilla.suse.com/show_bug.cgi?id=1263742 * https://bugzilla.suse.com/show_bug.cgi?id=1263743 * https://bugzilla.suse.com/show_bug.cgi?id=1263744 * https://bugzilla.suse.com/show_bug.cgi?id=1263745 * https://bugzilla.suse.com/show_bug.cgi?id=1263746 * https://bugzilla.suse.com/show_bug.cgi?id=1263747 * https://bugzilla.suse.com/show_bug.cgi?id=1263748 * https://bugzilla.suse.com/show_bug.cgi?id=1263749 * https://bugzilla.suse.com/show_bug.cgi?id=1263750 * https://bugzilla.suse.com/show_bug.cgi?id=1263751 * https://bugzilla.suse.com/show_bug.cgi?id=1263752 * https://bugzilla.suse.com/show_bug.cgi?id=1263753 * https://bugzilla.suse.com/show_bug.cgi?id=1263754 * https://bugzilla.suse.com/show_bug.cgi?id=1263755 * https://bugzilla.suse.com/show_bug.cgi?id=1263756 * https://bugzilla.suse.com/show_bug.cgi?id=1263757 * https://bugzilla.suse.com/show_bug.cgi?id=1263758 * https://bugzilla.suse.com/show_bug.cgi?id=1263759 * https://bugzilla.suse.com/show_bug.cgi?id=1263760 * https://bugzilla.suse.com/show_bug.cgi?id=1263761 * https://bugzilla.suse.com/show_bug.cgi?id=1263762 * https://bugzilla.suse.com/show_bug.cgi?id=1263765 * https://bugzilla.suse.com/show_bug.cgi?id=1263766 * https://bugzilla.suse.com/show_bug.cgi?id=1263767 * https://bugzilla.suse.com/show_bug.cgi?id=1263809 * https://bugzilla.suse.com/show_bug.cgi?id=1263810 * https://bugzilla.suse.com/show_bug.cgi?id=1266670 * https://bugzilla.suse.com/show_bug.cgi?id=1271133 * https://bugzilla.suse.com/show_bug.cgi?id=1271134 * https://bugzilla.suse.com/show_bug.cgi?id=1271135 * https://bugzilla.suse.com/show_bug.cgi?id=1271136 * https://bugzilla.suse.com/show_bug.cgi?id=1271137 * https://bugzilla.suse.com/show_bug.cgi?id=1271138 * https://bugzilla.suse.com/show_bug.cgi?id=1271139 * https://bugzilla.suse.com/show_bug.cgi?id=1271140 * https://bugzilla.suse.com/show_bug.cgi?id=1271141 * https://bugzilla.suse.com/show_bug.cgi?id=1271142 * https://bugzilla.suse.com/show_bug.cgi?id=1271143 * https://bugzilla.suse.com/show_bug.cgi?id=1271144 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 08:30:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 08:30:46 -0000 Subject: SUSE-SU-2026:3514-1: critical: Security update for php8 Message-ID: <178600504685.234.6135803076035579833@2d2f46e78665> # Security update for php8 Announcement ID: SUSE-SU-2026:3514-1 Release Date: 2026-08-05T18:29:07Z Rating: critical References: * bsc#1270351 * bsc#1273075 * bsc#1273077 * bsc#1273078 Cross-References: * CVE-2026-14355 * CVE-2026-17543 * CVE-2026-7260 * CVE-2026-9672 CVSS scores: * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-17543 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-17543 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-17543 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X * CVE-2026-17543 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7260 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7260 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9672 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for php8 fixes the following issues: Update to version 8.2.33. Security issues fixed: * CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). * CVE-2026-9672: security issues in `libgd` (bsc#1273078). * CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). * CVE-2026-14355: buffer allocation flaw in the AES-WRAP-PAD algorithm implementation can lead to heap metadata corruption and an application abort (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3514=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3514=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3514=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * php8-tidy-8.2.33-150600.3.33.1 * php8-zip-8.2.33-150600.3.33.1 * php8-bz2-8.2.33-150600.3.33.1 * php8-openssl-debuginfo-8.2.33-150600.3.33.1 * php8-sysvmsg-8.2.33-150600.3.33.1 * php8-phar-8.2.33-150600.3.33.1 * php8-xmlreader-8.2.33-150600.3.33.1 * php8-sqlite-debuginfo-8.2.33-150600.3.33.1 * php8-readline-8.2.33-150600.3.33.1 * php8-sockets-debuginfo-8.2.33-150600.3.33.1 * php8-bcmath-8.2.33-150600.3.33.1 * php8-fastcgi-debuginfo-8.2.33-150600.3.33.1 * php8-curl-debuginfo-8.2.33-150600.3.33.1 * php8-mbstring-debuginfo-8.2.33-150600.3.33.1 * php8-shmop-8.2.33-150600.3.33.1 * php8-sysvsem-8.2.33-150600.3.33.1 * php8-zip-debuginfo-8.2.33-150600.3.33.1 * php8-ffi-debuginfo-8.2.33-150600.3.33.1 * php8-gmp-8.2.33-150600.3.33.1 * php8-xmlwriter-debuginfo-8.2.33-150600.3.33.1 * php8-opcache-debuginfo-8.2.33-150600.3.33.1 * php8-tokenizer-8.2.33-150600.3.33.1 * php8-calendar-debuginfo-8.2.33-150600.3.33.1 * php8-enchant-8.2.33-150600.3.33.1 * php8-ftp-debuginfo-8.2.33-150600.3.33.1 * php8-embed-8.2.33-150600.3.33.1 * php8-pdo-debuginfo-8.2.33-150600.3.33.1 * php8-gmp-debuginfo-8.2.33-150600.3.33.1 * php8-dom-8.2.33-150600.3.33.1 * php8-posix-8.2.33-150600.3.33.1 * php8-debuginfo-8.2.33-150600.3.33.1 * php8-sysvshm-8.2.33-150600.3.33.1 * php8-phar-debuginfo-8.2.33-150600.3.33.1 * php8-sockets-8.2.33-150600.3.33.1 * apache2-mod_php8-debuginfo-8.2.33-150600.3.33.1 * php8-tokenizer-debuginfo-8.2.33-150600.3.33.1 * php8-bcmath-debuginfo-8.2.33-150600.3.33.1 * php8-xmlreader-debuginfo-8.2.33-150600.3.33.1 * php8-fileinfo-debuginfo-8.2.33-150600.3.33.1 * php8-sysvmsg-debuginfo-8.2.33-150600.3.33.1 * php8-sodium-8.2.33-150600.3.33.1 * php8-ctype-debuginfo-8.2.33-150600.3.33.1 * php8-ftp-8.2.33-150600.3.33.1 * php8-mysql-debuginfo-8.2.33-150600.3.33.1 * php8-iconv-8.2.33-150600.3.33.1 * php8-intl-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-8.2.33-150600.3.33.1 * php8-xsl-debuginfo-8.2.33-150600.3.33.1 * apache2-mod_php8-debugsource-8.2.33-150600.3.33.1 * php8-exif-debuginfo-8.2.33-150600.3.33.1 * php8-soap-debuginfo-8.2.33-150600.3.33.1 * php8-posix-debuginfo-8.2.33-150600.3.33.1 * php8-gd-debuginfo-8.2.33-150600.3.33.1 * php8-bz2-debuginfo-8.2.33-150600.3.33.1 * php8-dba-debuginfo-8.2.33-150600.3.33.1 * php8-pgsql-8.2.33-150600.3.33.1 * php8-ldap-8.2.33-150600.3.33.1 * php8-mysql-8.2.33-150600.3.33.1 * php8-mbstring-8.2.33-150600.3.33.1 * php8-gettext-8.2.33-150600.3.33.1 * php8-iconv-debuginfo-8.2.33-150600.3.33.1 * php8-tidy-debuginfo-8.2.33-150600.3.33.1 * php8-curl-8.2.33-150600.3.33.1 * php8-fileinfo-8.2.33-150600.3.33.1 * php8-sysvshm-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-debugsource-8.2.33-150600.3.33.1 * php8-test-8.2.33-150600.3.33.1 * php8-devel-8.2.33-150600.3.33.1 * php8-embed-debuginfo-8.2.33-150600.3.33.1 * php8-cli-8.2.33-150600.3.33.1 * php8-debugsource-8.2.33-150600.3.33.1 * php8-xmlwriter-8.2.33-150600.3.33.1 * php8-fastcgi-debugsource-8.2.33-150600.3.33.1 * php8-pcntl-debuginfo-8.2.33-150600.3.33.1 * php8-gd-8.2.33-150600.3.33.1 * php8-sysvsem-debuginfo-8.2.33-150600.3.33.1 * php8-sqlite-8.2.33-150600.3.33.1 * php8-pdo-8.2.33-150600.3.33.1 * php8-intl-8.2.33-150600.3.33.1 * php8-snmp-8.2.33-150600.3.33.1 * php8-8.2.33-150600.3.33.1 * php8-ldap-debuginfo-8.2.33-150600.3.33.1 * php8-opcache-8.2.33-150600.3.33.1 * php8-readline-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-debuginfo-8.2.33-150600.3.33.1 * php8-odbc-debuginfo-8.2.33-150600.3.33.1 * php8-embed-debugsource-8.2.33-150600.3.33.1 * php8-zlib-8.2.33-150600.3.33.1 * php8-dba-8.2.33-150600.3.33.1 * php8-fastcgi-8.2.33-150600.3.33.1 * php8-calendar-8.2.33-150600.3.33.1 * php8-zlib-debuginfo-8.2.33-150600.3.33.1 * php8-dom-debuginfo-8.2.33-150600.3.33.1 * php8-shmop-debuginfo-8.2.33-150600.3.33.1 * apache2-mod_php8-8.2.33-150600.3.33.1 * php8-soap-8.2.33-150600.3.33.1 * php8-exif-8.2.33-150600.3.33.1 * php8-ctype-8.2.33-150600.3.33.1 * php8-xsl-8.2.33-150600.3.33.1 * php8-gettext-debuginfo-8.2.33-150600.3.33.1 * php8-odbc-8.2.33-150600.3.33.1 * php8-cli-debuginfo-8.2.33-150600.3.33.1 * php8-sodium-debuginfo-8.2.33-150600.3.33.1 * php8-pcntl-8.2.33-150600.3.33.1 * php8-enchant-debuginfo-8.2.33-150600.3.33.1 * php8-snmp-debuginfo-8.2.33-150600.3.33.1 * php8-openssl-8.2.33-150600.3.33.1 * php8-pgsql-debuginfo-8.2.33-150600.3.33.1 * php8-ffi-8.2.33-150600.3.33.1 * openSUSE Leap 15.6 (noarch) * php8-fpm-apache-8.2.33-150600.3.33.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * php8-tidy-8.2.33-150600.3.33.1 * php8-zip-8.2.33-150600.3.33.1 * php8-bz2-8.2.33-150600.3.33.1 * php8-openssl-debuginfo-8.2.33-150600.3.33.1 * php8-sysvmsg-8.2.33-150600.3.33.1 * php8-xmlreader-8.2.33-150600.3.33.1 * php8-phar-8.2.33-150600.3.33.1 * php8-sqlite-debuginfo-8.2.33-150600.3.33.1 * php8-readline-8.2.33-150600.3.33.1 * php8-sockets-debuginfo-8.2.33-150600.3.33.1 * php8-bcmath-8.2.33-150600.3.33.1 * php8-fastcgi-debuginfo-8.2.33-150600.3.33.1 * php8-curl-debuginfo-8.2.33-150600.3.33.1 * php8-mbstring-debuginfo-8.2.33-150600.3.33.1 * php8-shmop-8.2.33-150600.3.33.1 * php8-sysvsem-8.2.33-150600.3.33.1 * php8-zip-debuginfo-8.2.33-150600.3.33.1 * php8-gmp-8.2.33-150600.3.33.1 * php8-xmlwriter-debuginfo-8.2.33-150600.3.33.1 * php8-opcache-debuginfo-8.2.33-150600.3.33.1 * php8-ftp-debuginfo-8.2.33-150600.3.33.1 * php8-gmp-debuginfo-8.2.33-150600.3.33.1 * php8-enchant-8.2.33-150600.3.33.1 * php8-embed-8.2.33-150600.3.33.1 * php8-calendar-debuginfo-8.2.33-150600.3.33.1 * php8-pdo-debuginfo-8.2.33-150600.3.33.1 * php8-tokenizer-8.2.33-150600.3.33.1 * php8-dom-8.2.33-150600.3.33.1 * php8-posix-8.2.33-150600.3.33.1 * php8-debuginfo-8.2.33-150600.3.33.1 * php8-sysvshm-8.2.33-150600.3.33.1 * php8-phar-debuginfo-8.2.33-150600.3.33.1 * php8-sockets-8.2.33-150600.3.33.1 * apache2-mod_php8-debuginfo-8.2.33-150600.3.33.1 * php8-tokenizer-debuginfo-8.2.33-150600.3.33.1 * php8-bcmath-debuginfo-8.2.33-150600.3.33.1 * php8-xmlreader-debuginfo-8.2.33-150600.3.33.1 * php8-fileinfo-debuginfo-8.2.33-150600.3.33.1 * php8-sysvmsg-debuginfo-8.2.33-150600.3.33.1 * php8-sodium-8.2.33-150600.3.33.1 * php8-ctype-debuginfo-8.2.33-150600.3.33.1 * php8-ftp-8.2.33-150600.3.33.1 * php8-mysql-debuginfo-8.2.33-150600.3.33.1 * php8-iconv-8.2.33-150600.3.33.1 * php8-fpm-8.2.33-150600.3.33.1 * php8-intl-debuginfo-8.2.33-150600.3.33.1 * php8-xsl-debuginfo-8.2.33-150600.3.33.1 * php8-exif-debuginfo-8.2.33-150600.3.33.1 * apache2-mod_php8-debugsource-8.2.33-150600.3.33.1 * php8-soap-debuginfo-8.2.33-150600.3.33.1 * php8-posix-debuginfo-8.2.33-150600.3.33.1 * php8-gd-debuginfo-8.2.33-150600.3.33.1 * php8-bz2-debuginfo-8.2.33-150600.3.33.1 * php8-dba-debuginfo-8.2.33-150600.3.33.1 * php8-pgsql-8.2.33-150600.3.33.1 * php8-ldap-8.2.33-150600.3.33.1 * php8-mysql-8.2.33-150600.3.33.1 * php8-mbstring-8.2.33-150600.3.33.1 * php8-gettext-8.2.33-150600.3.33.1 * php8-iconv-debuginfo-8.2.33-150600.3.33.1 * php8-tidy-debuginfo-8.2.33-150600.3.33.1 * php8-curl-8.2.33-150600.3.33.1 * php8-fileinfo-8.2.33-150600.3.33.1 * php8-sysvshm-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-debugsource-8.2.33-150600.3.33.1 * php8-test-8.2.33-150600.3.33.1 * php8-devel-8.2.33-150600.3.33.1 * php8-embed-debuginfo-8.2.33-150600.3.33.1 * php8-cli-8.2.33-150600.3.33.1 * php8-debugsource-8.2.33-150600.3.33.1 * php8-xmlwriter-8.2.33-150600.3.33.1 * php8-fastcgi-debugsource-8.2.33-150600.3.33.1 * php8-pcntl-debuginfo-8.2.33-150600.3.33.1 * php8-gd-8.2.33-150600.3.33.1 * php8-sysvsem-debuginfo-8.2.33-150600.3.33.1 * php8-sqlite-8.2.33-150600.3.33.1 * php8-pdo-8.2.33-150600.3.33.1 * php8-snmp-8.2.33-150600.3.33.1 * php8-intl-8.2.33-150600.3.33.1 * php8-8.2.33-150600.3.33.1 * php8-ldap-debuginfo-8.2.33-150600.3.33.1 * php8-opcache-8.2.33-150600.3.33.1 * php8-readline-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-debuginfo-8.2.33-150600.3.33.1 * php8-odbc-debuginfo-8.2.33-150600.3.33.1 * php8-embed-debugsource-8.2.33-150600.3.33.1 * php8-zlib-8.2.33-150600.3.33.1 * php8-dba-8.2.33-150600.3.33.1 * php8-fastcgi-8.2.33-150600.3.33.1 * php8-zlib-debuginfo-8.2.33-150600.3.33.1 * php8-calendar-8.2.33-150600.3.33.1 * php8-dom-debuginfo-8.2.33-150600.3.33.1 * php8-shmop-debuginfo-8.2.33-150600.3.33.1 * apache2-mod_php8-8.2.33-150600.3.33.1 * php8-soap-8.2.33-150600.3.33.1 * php8-exif-8.2.33-150600.3.33.1 * php8-ctype-8.2.33-150600.3.33.1 * php8-xsl-8.2.33-150600.3.33.1 * php8-gettext-debuginfo-8.2.33-150600.3.33.1 * php8-odbc-8.2.33-150600.3.33.1 * php8-cli-debuginfo-8.2.33-150600.3.33.1 * php8-sodium-debuginfo-8.2.33-150600.3.33.1 * php8-pcntl-8.2.33-150600.3.33.1 * php8-enchant-debuginfo-8.2.33-150600.3.33.1 * php8-snmp-debuginfo-8.2.33-150600.3.33.1 * php8-openssl-8.2.33-150600.3.33.1 * php8-pgsql-debuginfo-8.2.33-150600.3.33.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * php8-tidy-8.2.33-150600.3.33.1 * php8-zip-8.2.33-150600.3.33.1 * php8-bz2-8.2.33-150600.3.33.1 * php8-openssl-debuginfo-8.2.33-150600.3.33.1 * php8-sysvmsg-8.2.33-150600.3.33.1 * php8-phar-8.2.33-150600.3.33.1 * php8-xmlreader-8.2.33-150600.3.33.1 * php8-sqlite-debuginfo-8.2.33-150600.3.33.1 * php8-readline-8.2.33-150600.3.33.1 * php8-sockets-debuginfo-8.2.33-150600.3.33.1 * php8-bcmath-8.2.33-150600.3.33.1 * php8-fastcgi-debuginfo-8.2.33-150600.3.33.1 * php8-curl-debuginfo-8.2.33-150600.3.33.1 * php8-mbstring-debuginfo-8.2.33-150600.3.33.1 * php8-shmop-8.2.33-150600.3.33.1 * php8-sysvsem-8.2.33-150600.3.33.1 * php8-zip-debuginfo-8.2.33-150600.3.33.1 * php8-gmp-8.2.33-150600.3.33.1 * php8-xmlwriter-debuginfo-8.2.33-150600.3.33.1 * php8-opcache-debuginfo-8.2.33-150600.3.33.1 * php8-ftp-debuginfo-8.2.33-150600.3.33.1 * php8-calendar-debuginfo-8.2.33-150600.3.33.1 * php8-tokenizer-8.2.33-150600.3.33.1 * php8-gmp-debuginfo-8.2.33-150600.3.33.1 * php8-embed-8.2.33-150600.3.33.1 * php8-pdo-debuginfo-8.2.33-150600.3.33.1 * php8-enchant-8.2.33-150600.3.33.1 * php8-dom-8.2.33-150600.3.33.1 * php8-posix-8.2.33-150600.3.33.1 * php8-debuginfo-8.2.33-150600.3.33.1 * php8-sysvshm-8.2.33-150600.3.33.1 * php8-phar-debuginfo-8.2.33-150600.3.33.1 * php8-sockets-8.2.33-150600.3.33.1 * apache2-mod_php8-debuginfo-8.2.33-150600.3.33.1 * php8-tokenizer-debuginfo-8.2.33-150600.3.33.1 * php8-bcmath-debuginfo-8.2.33-150600.3.33.1 * php8-xmlreader-debuginfo-8.2.33-150600.3.33.1 * php8-fileinfo-debuginfo-8.2.33-150600.3.33.1 * php8-sysvmsg-debuginfo-8.2.33-150600.3.33.1 * php8-sodium-8.2.33-150600.3.33.1 * php8-ctype-debuginfo-8.2.33-150600.3.33.1 * php8-ftp-8.2.33-150600.3.33.1 * php8-mysql-debuginfo-8.2.33-150600.3.33.1 * php8-iconv-8.2.33-150600.3.33.1 * php8-intl-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-8.2.33-150600.3.33.1 * php8-xsl-debuginfo-8.2.33-150600.3.33.1 * php8-exif-debuginfo-8.2.33-150600.3.33.1 * apache2-mod_php8-debugsource-8.2.33-150600.3.33.1 * php8-soap-debuginfo-8.2.33-150600.3.33.1 * php8-posix-debuginfo-8.2.33-150600.3.33.1 * php8-gd-debuginfo-8.2.33-150600.3.33.1 * php8-bz2-debuginfo-8.2.33-150600.3.33.1 * php8-dba-debuginfo-8.2.33-150600.3.33.1 * php8-pgsql-8.2.33-150600.3.33.1 * php8-ldap-8.2.33-150600.3.33.1 * php8-mysql-8.2.33-150600.3.33.1 * php8-mbstring-8.2.33-150600.3.33.1 * php8-gettext-8.2.33-150600.3.33.1 * php8-iconv-debuginfo-8.2.33-150600.3.33.1 * php8-tidy-debuginfo-8.2.33-150600.3.33.1 * php8-curl-8.2.33-150600.3.33.1 * php8-fileinfo-8.2.33-150600.3.33.1 * php8-sysvshm-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-debugsource-8.2.33-150600.3.33.1 * php8-test-8.2.33-150600.3.33.1 * php8-devel-8.2.33-150600.3.33.1 * php8-embed-debuginfo-8.2.33-150600.3.33.1 * php8-cli-8.2.33-150600.3.33.1 * php8-debugsource-8.2.33-150600.3.33.1 * php8-xmlwriter-8.2.33-150600.3.33.1 * php8-fastcgi-debugsource-8.2.33-150600.3.33.1 * php8-pcntl-debuginfo-8.2.33-150600.3.33.1 * php8-gd-8.2.33-150600.3.33.1 * php8-sqlite-8.2.33-150600.3.33.1 * php8-sysvsem-debuginfo-8.2.33-150600.3.33.1 * php8-intl-8.2.33-150600.3.33.1 * php8-snmp-8.2.33-150600.3.33.1 * php8-pdo-8.2.33-150600.3.33.1 * php8-8.2.33-150600.3.33.1 * php8-ldap-debuginfo-8.2.33-150600.3.33.1 * php8-opcache-8.2.33-150600.3.33.1 * php8-readline-debuginfo-8.2.33-150600.3.33.1 * php8-fpm-debuginfo-8.2.33-150600.3.33.1 * php8-odbc-debuginfo-8.2.33-150600.3.33.1 * php8-embed-debugsource-8.2.33-150600.3.33.1 * php8-zlib-8.2.33-150600.3.33.1 * php8-dba-8.2.33-150600.3.33.1 * php8-fastcgi-8.2.33-150600.3.33.1 * php8-zlib-debuginfo-8.2.33-150600.3.33.1 * php8-calendar-8.2.33-150600.3.33.1 * php8-dom-debuginfo-8.2.33-150600.3.33.1 * php8-shmop-debuginfo-8.2.33-150600.3.33.1 * apache2-mod_php8-8.2.33-150600.3.33.1 * php8-soap-8.2.33-150600.3.33.1 * php8-exif-8.2.33-150600.3.33.1 * php8-ctype-8.2.33-150600.3.33.1 * php8-xsl-8.2.33-150600.3.33.1 * php8-gettext-debuginfo-8.2.33-150600.3.33.1 * php8-odbc-8.2.33-150600.3.33.1 * php8-cli-debuginfo-8.2.33-150600.3.33.1 * php8-sodium-debuginfo-8.2.33-150600.3.33.1 * php8-pcntl-8.2.33-150600.3.33.1 * php8-enchant-debuginfo-8.2.33-150600.3.33.1 * php8-snmp-debuginfo-8.2.33-150600.3.33.1 * php8-openssl-8.2.33-150600.3.33.1 * php8-pgsql-debuginfo-8.2.33-150600.3.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14355.html * https://www.suse.com/security/cve/CVE-2026-17543.html * https://www.suse.com/security/cve/CVE-2026-7260.html * https://www.suse.com/security/cve/CVE-2026-9672.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 * https://bugzilla.suse.com/show_bug.cgi?id=1273075 * https://bugzilla.suse.com/show_bug.cgi?id=1273077 * https://bugzilla.suse.com/show_bug.cgi?id=1273078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 08:31:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 08:31:58 -0000 Subject: SUSE-SU-2026:3513-1: critical: Security update for php8 Message-ID: <178600511862.234.6105304007616333172@2d2f46e78665> # Security update for php8 Announcement ID: SUSE-SU-2026:3513-1 Release Date: 2026-08-05T18:28:54Z Rating: critical References: * bsc#1273075 * bsc#1273077 * bsc#1273078 Cross-References: * CVE-2026-17543 * CVE-2026-7260 * CVE-2026-9672 CVSS scores: * CVE-2026-17543 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-17543 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-17543 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:U/V:X/RE:X/U:X * CVE-2026-17543 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7260 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7260 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9672 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for php8 fixes the following issues: * CVE-2026-7260: circular symbolic links in phar archives can lead to unbounded recursion and cause C stack exhaustion (bsc#1273077). * CVE-2026-9672: security issues in `libgd` (bsc#1273078). * CVE-2026-17543: improper escaping of backslashes in user-provided parameters allows for trivial SQL injection in `ext-pgsql` (bsc#1273075). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3513=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3513=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3513=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3513=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3513=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3513=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3513=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3513=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3513=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * php8-sodium-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-8.0.30-150400.4.73.1 * php8-snmp-8.0.30-150400.4.73.1 * php8-fastcgi-debugsource-8.0.30-150400.4.73.1 * php8-fpm-debugsource-8.0.30-150400.4.73.1 * php8-sqlite-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-debuginfo-8.0.30-150400.4.73.1 * php8-sysvsem-8.0.30-150400.4.73.1 * php8-ldap-debuginfo-8.0.30-150400.4.73.1 * php8-dba-8.0.30-150400.4.73.1 * php8-gmp-debuginfo-8.0.30-150400.4.73.1 * php8-pcntl-8.0.30-150400.4.73.1 * php8-mysql-8.0.30-150400.4.73.1 * php8-ftp-8.0.30-150400.4.73.1 * php8-soap-8.0.30-150400.4.73.1 * php8-pgsql-8.0.30-150400.4.73.1 * php8-xsl-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-debuginfo-8.0.30-150400.4.73.1 * php8-sodium-8.0.30-150400.4.73.1 * php8-enchant-8.0.30-150400.4.73.1 * php8-ctype-debuginfo-8.0.30-150400.4.73.1 * php8-dba-debuginfo-8.0.30-150400.4.73.1 * php8-test-8.0.30-150400.4.73.1 * php8-exif-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debugsource-8.0.30-150400.4.73.1 * php8-mbstring-8.0.30-150400.4.73.1 * php8-pcntl-debuginfo-8.0.30-150400.4.73.1 * php8-bcmath-8.0.30-150400.4.73.1 * php8-sqlite-8.0.30-150400.4.73.1 * php8-8.0.30-150400.4.73.1 * php8-curl-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.73.1 * php8-readline-8.0.30-150400.4.73.1 * php8-sockets-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-8.0.30-150400.4.73.1 * php8-zip-8.0.30-150400.4.73.1 * php8-iconv-8.0.30-150400.4.73.1 * php8-zip-debuginfo-8.0.30-150400.4.73.1 * php8-iconv-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-8.0.30-150400.4.73.1 * php8-sockets-8.0.30-150400.4.73.1 * php8-ctype-8.0.30-150400.4.73.1 * php8-phar-debuginfo-8.0.30-150400.4.73.1 * php8-dom-debuginfo-8.0.30-150400.4.73.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.73.1 * php8-mysql-debuginfo-8.0.30-150400.4.73.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.73.1 * php8-readline-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-8.0.30-150400.4.73.1 * php8-debuginfo-8.0.30-150400.4.73.1 * php8-sysvmsg-8.0.30-150400.4.73.1 * php8-phar-8.0.30-150400.4.73.1 * php8-xmlwriter-8.0.30-150400.4.73.1 * php8-xmlreader-8.0.30-150400.4.73.1 * php8-dom-8.0.30-150400.4.73.1 * php8-xsl-8.0.30-150400.4.73.1 * php8-opcache-8.0.30-150400.4.73.1 * php8-openssl-8.0.30-150400.4.73.1 * php8-enchant-debuginfo-8.0.30-150400.4.73.1 * php8-fpm-8.0.30-150400.4.73.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-8.0.30-150400.4.73.1 * php8-zlib-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-debuginfo-8.0.30-150400.4.73.1 * php8-mbstring-debuginfo-8.0.30-150400.4.73.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.73.1 * php8-opcache-debuginfo-8.0.30-150400.4.73.1 * php8-bz2-8.0.30-150400.4.73.1 * php8-devel-8.0.30-150400.4.73.1 * php8-debugsource-8.0.30-150400.4.73.1 * php8-cli-debuginfo-8.0.30-150400.4.73.1 * php8-posix-debuginfo-8.0.30-150400.4.73.1 * php8-cli-8.0.30-150400.4.73.1 * php8-tokenizer-8.0.30-150400.4.73.1 * php8-ldap-8.0.30-150400.4.73.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.73.1 * php8-ftp-debuginfo-8.0.30-150400.4.73.1 * php8-tidy-debuginfo-8.0.30-150400.4.73.1 * php8-curl-8.0.30-150400.4.73.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.73.1 * php8-gettext-8.0.30-150400.4.73.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-8.0.30-150400.4.73.1 * php8-gmp-8.0.30-150400.4.73.1 * php8-gd-8.0.30-150400.4.73.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.73.1 * php8-intl-debuginfo-8.0.30-150400.4.73.1 * php8-calendar-debuginfo-8.0.30-150400.4.73.1 * php8-odbc-debuginfo-8.0.30-150400.4.73.1 * php8-soap-debuginfo-8.0.30-150400.4.73.1 * php8-posix-8.0.30-150400.4.73.1 * php8-gettext-debuginfo-8.0.30-150400.4.73.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.73.1 * php8-zlib-8.0.30-150400.4.73.1 * php8-bcmath-debuginfo-8.0.30-150400.4.73.1 * php8-embed-debuginfo-8.0.30-150400.4.73.1 * php8-pdo-8.0.30-150400.4.73.1 * php8-intl-8.0.30-150400.4.73.1 * php8-snmp-debuginfo-8.0.30-150400.4.73.1 * php8-pgsql-debuginfo-8.0.30-150400.4.73.1 * php8-openssl-debuginfo-8.0.30-150400.4.73.1 * php8-exif-8.0.30-150400.4.73.1 * php8-gd-debuginfo-8.0.30-150400.4.73.1 * php8-shmop-8.0.30-150400.4.73.1 * php8-odbc-8.0.30-150400.4.73.1 * php8-embed-8.0.30-150400.4.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-17543.html * https://www.suse.com/security/cve/CVE-2026-7260.html * https://www.suse.com/security/cve/CVE-2026-9672.html * https://bugzilla.suse.com/show_bug.cgi?id=1273075 * https://bugzilla.suse.com/show_bug.cgi?id=1273077 * https://bugzilla.suse.com/show_bug.cgi?id=1273078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 16:30:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 16:30:57 -0000 Subject: SUSE-SU-2026:3521-1: important: Security update for nodejs22 Message-ID: <178603385738.242.11564730283816820668@70aaff0f9d46> # Security update for nodejs22 Announcement ID: SUSE-SU-2026:3521-1 Release Date: 2026-08-06T11:31:28Z Rating: important References: * bsc#1272882 * bsc#1272941 * bsc#1272942 * bsc#1272943 * bsc#1272944 * bsc#1272945 * bsc#1272947 * bsc#1272948 * bsc#1272949 * bsc#1272950 * bsc#1272951 Cross-References: * CVE-2026-54272 * CVE-2026-56846 * CVE-2026-56847 * CVE-2026-56848 * CVE-2026-56850 * CVE-2026-58039 * CVE-2026-58040 * CVE-2026-58042 * CVE-2026-58043 * CVE-2026-58044 * CVE-2026-58045 CVSS scores: * CVE-2026-54272 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-54272 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56846 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56847 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.1 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58039 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58040 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58040 ( NVD ): 6.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58042 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 7.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58044 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58045 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for nodejs22 fixes the following issues: Update to 22.23.2. * CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). * CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). * CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). * CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). * CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). * CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). * CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). * CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3521=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3521=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3521=1 ## Package List: * openSUSE Leap 15.6 (noarch) * nodejs22-docs-22.23.2-150600.13.24.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nodejs22-devel-22.23.2-150600.13.24.1 * npm22-22.23.2-150600.13.24.1 * corepack22-22.23.2-150600.13.24.1 * nodejs22-22.23.2-150600.13.24.1 * nodejs22-debugsource-22.23.2-150600.13.24.1 * nodejs22-debuginfo-22.23.2-150600.13.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nodejs22-devel-22.23.2-150600.13.24.1 * npm22-22.23.2-150600.13.24.1 * nodejs22-22.23.2-150600.13.24.1 * nodejs22-debugsource-22.23.2-150600.13.24.1 * nodejs22-debuginfo-22.23.2-150600.13.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nodejs22-docs-22.23.2-150600.13.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nodejs22-devel-22.23.2-150600.13.24.1 * npm22-22.23.2-150600.13.24.1 * nodejs22-22.23.2-150600.13.24.1 * nodejs22-debugsource-22.23.2-150600.13.24.1 * nodejs22-debuginfo-22.23.2-150600.13.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nodejs22-docs-22.23.2-150600.13.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54272.html * https://www.suse.com/security/cve/CVE-2026-56846.html * https://www.suse.com/security/cve/CVE-2026-56847.html * https://www.suse.com/security/cve/CVE-2026-56848.html * https://www.suse.com/security/cve/CVE-2026-56850.html * https://www.suse.com/security/cve/CVE-2026-58039.html * https://www.suse.com/security/cve/CVE-2026-58040.html * https://www.suse.com/security/cve/CVE-2026-58042.html * https://www.suse.com/security/cve/CVE-2026-58043.html * https://www.suse.com/security/cve/CVE-2026-58044.html * https://www.suse.com/security/cve/CVE-2026-58045.html * https://bugzilla.suse.com/show_bug.cgi?id=1272882 * https://bugzilla.suse.com/show_bug.cgi?id=1272941 * https://bugzilla.suse.com/show_bug.cgi?id=1272942 * https://bugzilla.suse.com/show_bug.cgi?id=1272943 * https://bugzilla.suse.com/show_bug.cgi?id=1272944 * https://bugzilla.suse.com/show_bug.cgi?id=1272945 * https://bugzilla.suse.com/show_bug.cgi?id=1272947 * https://bugzilla.suse.com/show_bug.cgi?id=1272948 * https://bugzilla.suse.com/show_bug.cgi?id=1272949 * https://bugzilla.suse.com/show_bug.cgi?id=1272950 * https://bugzilla.suse.com/show_bug.cgi?id=1272951 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 16:32:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 16:32:09 -0000 Subject: SUSE-SU-2026:3520-1: important: Security update for nodejs24 Message-ID: <178603392987.242.12860396156656408026@70aaff0f9d46> # Security update for nodejs24 Announcement ID: SUSE-SU-2026:3520-1 Release Date: 2026-08-06T11:31:17Z Rating: important References: * bsc#1269825 * bsc#1272882 * bsc#1272941 * bsc#1272942 * bsc#1272943 * bsc#1272944 * bsc#1272945 * bsc#1272946 * bsc#1272947 * bsc#1272948 * bsc#1272949 * bsc#1272950 * bsc#1272951 Cross-References: * CVE-2026-54272 * CVE-2026-56846 * CVE-2026-56847 * CVE-2026-56848 * CVE-2026-56850 * CVE-2026-58039 * CVE-2026-58040 * CVE-2026-58041 * CVE-2026-58042 * CVE-2026-58043 * CVE-2026-58044 * CVE-2026-58045 CVSS scores: * CVE-2026-54272 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-54272 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56846 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56847 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.1 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58039 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58040 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58040 ( NVD ): 6.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58041 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-58041 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-58041 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58042 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 7.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58044 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58045 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves 12 vulnerabilities and has one security fix can now be installed. ## Description: This update for nodejs24 fixes the following issues: Update to 24.18.1. * CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). * CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). * CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). * CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). * CVE-2026-58041: `node:sqlite` `SQLTagStore` iterator replay can re-execute writes (bsc#1272946). * CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). * CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). * CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). * CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). Other updates and bugfixes: * Version 24.18.0: * fix: severe regression in security update 24.17 of nodejs24 (bsc#1269825) * doc: update blockList stability status to release candidate * fs: support caller-supplied readFile() buffers * http: close pre-request sockets in closeIdleConnections * loader: implement package maps * net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive * tls: add certificateCompression option * vfs: dispatch node:fs/promises to mounted VFS instances * vfs: add minimal node:vfs subsystem ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3520=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * nodejs24-docs-24.18.1-150700.15.16.1 * Web and Scripting Module 15-SP7 (aarch64 ppc64le s390x x86_64) * npm24-24.18.1-150700.15.16.1 * nodejs24-24.18.1-150700.15.16.1 * nodejs24-debugsource-24.18.1-150700.15.16.1 * nodejs24-debuginfo-24.18.1-150700.15.16.1 * nodejs24-devel-24.18.1-150700.15.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54272.html * https://www.suse.com/security/cve/CVE-2026-56846.html * https://www.suse.com/security/cve/CVE-2026-56847.html * https://www.suse.com/security/cve/CVE-2026-56848.html * https://www.suse.com/security/cve/CVE-2026-56850.html * https://www.suse.com/security/cve/CVE-2026-58039.html * https://www.suse.com/security/cve/CVE-2026-58040.html * https://www.suse.com/security/cve/CVE-2026-58041.html * https://www.suse.com/security/cve/CVE-2026-58042.html * https://www.suse.com/security/cve/CVE-2026-58043.html * https://www.suse.com/security/cve/CVE-2026-58044.html * https://www.suse.com/security/cve/CVE-2026-58045.html * https://bugzilla.suse.com/show_bug.cgi?id=1269825 * https://bugzilla.suse.com/show_bug.cgi?id=1272882 * https://bugzilla.suse.com/show_bug.cgi?id=1272941 * https://bugzilla.suse.com/show_bug.cgi?id=1272942 * https://bugzilla.suse.com/show_bug.cgi?id=1272943 * https://bugzilla.suse.com/show_bug.cgi?id=1272944 * https://bugzilla.suse.com/show_bug.cgi?id=1272945 * https://bugzilla.suse.com/show_bug.cgi?id=1272946 * https://bugzilla.suse.com/show_bug.cgi?id=1272947 * https://bugzilla.suse.com/show_bug.cgi?id=1272948 * https://bugzilla.suse.com/show_bug.cgi?id=1272949 * https://bugzilla.suse.com/show_bug.cgi?id=1272950 * https://bugzilla.suse.com/show_bug.cgi?id=1272951 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 16:32:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 16:32:50 -0000 Subject: SUSE-SU-2026:3518-1: important: Security update for rsyslog Message-ID: <178603397076.242.15416984757501060374@70aaff0f9d46> # Security update for rsyslog Announcement ID: SUSE-SU-2026:3518-1 Release Date: 2026-08-06T11:21:57Z Rating: important References: * bsc#1271910 * bsc#1272414 Cross-References: * CVE-2026-61548 CVSS scores: * CVE-2026-61548 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for rsyslog fixes the following issues: * CVE-2026-61548: crafted RFC 5424 messages to mmpstrucdata can lead to a stack overwrite (bsc#1272414). * Input sequence during oversize-frame recovery in imptcp can cause denial of service (bsc#1271910). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3518=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3518=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3518=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3518=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3518=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3518=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3518=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3518=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3518=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * rsyslog-module-dbi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-omamqp1-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-kafka-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-gcrypt-8.2306.0-150400.5.40.1 * rsyslog-module-gcrypt-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-doc-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-diag-tools-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-omamqp1-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-kafka-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-omhttpfs-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-dbi-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-elasticsearch-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-omhttpfs-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-elasticsearch-8.2306.0-150400.5.40.1 * rsyslog-module-omtcl-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-omtcl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-diag-tools-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rsyslog-module-gtls-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-mysql-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-debugsource-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-8.2306.0-150400.5.40.1 * rsyslog-module-pgsql-8.2306.0-150400.5.40.1 * rsyslog-module-mmnormalize-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-snmp-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-8.2306.0-150400.5.40.1 * rsyslog-module-ossl-8.2306.0-150400.5.40.1 * rsyslog-8.2306.0-150400.5.40.1 * rsyslog-module-gssapi-debuginfo-8.2306.0-150400.5.40.1 * rsyslog-module-gtls-8.2306.0-150400.5.40.1 * rsyslog-module-relp-8.2306.0-150400.5.40.1 * rsyslog-module-udpspoof-8.2306.0-150400.5.40.1 * rsyslog-module-relp-debuginfo-8.2306.0-150400.5.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-61548.html * https://bugzilla.suse.com/show_bug.cgi?id=1271910 * https://bugzilla.suse.com/show_bug.cgi?id=1272414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 16:33:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 16:33:58 -0000 Subject: SUSE-SU-2026:3517-1: important: Security update for bind Message-ID: <178603403877.242.16619827066344535080@70aaff0f9d46> # Security update for bind Announcement ID: SUSE-SU-2026:3517-1 Release Date: 2026-08-06T11:20:17Z Rating: important References: * bsc#1207471 * bsc#1265591 * bsc#1265592 * bsc#1265594 * bsc#1271982 * bsc#1271984 * bsc#1271986 * bsc#1271987 * bsc#1271989 * bsc#1271990 Cross-References: * CVE-2022-3094 * CVE-2026-10723 * CVE-2026-11331 * CVE-2026-11622 * CVE-2026-11721 * CVE-2026-13204 * CVE-2026-13321 * CVE-2026-3039 * CVE-2026-3592 * CVE-2026-5946 CVSS scores: * CVE-2022-3094 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-3094 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10723 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-10723 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-10723 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-11331 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11331 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11331 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11721 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11721 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11721 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-13204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-13321 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-13321 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-13321 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-3039 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3592 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-3592 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Manager Client Tools for SLE Micro 5 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2022-3094: UPDATE message flood may cause `named` to exhaust all available memory (bsc#1207471). * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: invalid handling of `CLASS != IN` (bsc#1265594). * CVE-2026-10723: incorrect acceptance of NSEC3 records (bsc#1271982). * CVE-2026-11331: potential wildcard CNAME RPZ policy bypass (bsc#1271984). * CVE-2026-11622: potential memory usage beyond configured limits (bsc#1271986). * CVE-2026-11721: cache poisoning possible with label count discrepancy, RRSIG, and wildcards (bsc#1271987). * CVE-2026-13204: unexpected exit in certain situations with NSEC and NSEC3 both present (bsc#1271989). * CVE-2026-13321: DNSSEC validation bypass via out-of-zone NSEC Next field (bsc#1271990). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-SLE-Manager-Tools-For-Micro-5-2026-3517=1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-3517=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * bind-debugsource-9.16.6-150000.12.91.1 * bind-debuginfo-9.16.6-150000.12.91.1 * libisccc1600-debuginfo-9.16.6-150000.12.91.1 * libbind9-1600-debuginfo-9.16.6-150000.12.91.1 * libisc1606-debuginfo-9.16.6-150000.12.91.1 * libisccc1600-9.16.6-150000.12.91.1 * libisccfg1600-9.16.6-150000.12.91.1 * libirs1601-9.16.6-150000.12.91.1 * libdns1605-9.16.6-150000.12.91.1 * libisccfg1600-debuginfo-9.16.6-150000.12.91.1 * libbind9-1600-9.16.6-150000.12.91.1 * libns1604-debuginfo-9.16.6-150000.12.91.1 * bind-utils-9.16.6-150000.12.91.1 * libns1604-9.16.6-150000.12.91.1 * libdns1605-debuginfo-9.16.6-150000.12.91.1 * bind-utils-debuginfo-9.16.6-150000.12.91.1 * libirs1601-debuginfo-9.16.6-150000.12.91.1 * libisc1606-9.16.6-150000.12.91.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.91.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64 s390x x86_64) * libisccc1600-9.16.6-150000.12.91.1 * libdns1605-9.16.6-150000.12.91.1 * libisccfg1600-9.16.6-150000.12.91.1 * libirs1601-9.16.6-150000.12.91.1 * libns1604-debuginfo-9.16.6-150000.12.91.1 * libbind9-1600-9.16.6-150000.12.91.1 * bind-utils-9.16.6-150000.12.91.1 * libns1604-9.16.6-150000.12.91.1 * libisc1606-9.16.6-150000.12.91.1 * SUSE Manager Client Tools for SLE Micro 5 (noarch) * python3-bind-9.16.6-150000.12.91.1 * SUSE Manager Client Tools for SLE Micro 5 (aarch64_ilp32) * libisccfg1600-64bit-9.16.6-150000.12.91.1 * libirs1601-64bit-9.16.6-150000.12.91.1 * libisccc1600-64bit-9.16.6-150000.12.91.1 * libbind9-1600-64bit-9.16.6-150000.12.91.1 * libdns1605-64bit-9.16.6-150000.12.91.1 * libisc1606-64bit-9.16.6-150000.12.91.1 ## References: * https://www.suse.com/security/cve/CVE-2022-3094.html * https://www.suse.com/security/cve/CVE-2026-10723.html * https://www.suse.com/security/cve/CVE-2026-11331.html * https://www.suse.com/security/cve/CVE-2026-11622.html * https://www.suse.com/security/cve/CVE-2026-11721.html * https://www.suse.com/security/cve/CVE-2026-13204.html * https://www.suse.com/security/cve/CVE-2026-13321.html * https://www.suse.com/security/cve/CVE-2026-3039.html * https://www.suse.com/security/cve/CVE-2026-3592.html * https://www.suse.com/security/cve/CVE-2026-5946.html * https://bugzilla.suse.com/show_bug.cgi?id=1207471 * https://bugzilla.suse.com/show_bug.cgi?id=1265591 * https://bugzilla.suse.com/show_bug.cgi?id=1265592 * https://bugzilla.suse.com/show_bug.cgi?id=1265594 * https://bugzilla.suse.com/show_bug.cgi?id=1271982 * https://bugzilla.suse.com/show_bug.cgi?id=1271984 * https://bugzilla.suse.com/show_bug.cgi?id=1271986 * https://bugzilla.suse.com/show_bug.cgi?id=1271987 * https://bugzilla.suse.com/show_bug.cgi?id=1271989 * https://bugzilla.suse.com/show_bug.cgi?id=1271990 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 16:34:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 16:34:46 -0000 Subject: SUSE-SU-2026:3516-1: important: Security update for openssl-3 Message-ID: <178603408657.242.1931580403132426247@70aaff0f9d46> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3516-1 Release Date: 2026-08-06T11:09:20Z Rating: important References: * bsc#1271712 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one security fix can now be installed. ## Description: This update for openssl-3 fixes the following issue * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3516=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3516=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3516=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-devel-3.1.4-150600.5.59.1 * openssl-3-debugsource-3.1.4-150600.5.59.1 * openssl-3-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-3.1.4-150600.5.59.1 * libopenssl3-debuginfo-3.1.4-150600.5.59.1 * libopenssl3-3.1.4-150600.5.59.1 * openssl-3-3.1.4-150600.5.59.1 * openSUSE Leap 15.6 (x86_64) * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.59.1 * libopenssl3-32bit-3.1.4-150600.5.59.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-devel-32bit-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.59.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl-3-fips-provider-64bit-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-devel-64bit-3.1.4-150600.5.59.1 * libopenssl3-64bit-debuginfo-3.1.4-150600.5.59.1 * libopenssl3-64bit-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-64bit-3.1.4-150600.5.59.1 * openSUSE Leap 15.6 (noarch) * openssl-3-doc-3.1.4-150600.5.59.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-devel-3.1.4-150600.5.59.1 * openssl-3-debugsource-3.1.4-150600.5.59.1 * openssl-3-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-3.1.4-150600.5.59.1 * libopenssl3-debuginfo-3.1.4-150600.5.59.1 * libopenssl3-3.1.4-150600.5.59.1 * openssl-3-3.1.4-150600.5.59.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.59.1 * libopenssl3-32bit-3.1.4-150600.5.59.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.59.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-devel-3.1.4-150600.5.59.1 * openssl-3-debugsource-3.1.4-150600.5.59.1 * openssl-3-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-3.1.4-150600.5.59.1 * libopenssl3-debuginfo-3.1.4-150600.5.59.1 * openssl-3-3.1.4-150600.5.59.1 * libopenssl3-3.1.4-150600.5.59.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.59.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.59.1 * libopenssl3-32bit-3.1.4-150600.5.59.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.59.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Aug 6 16:35:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 06 Aug 2026 16:35:42 -0000 Subject: SUSE-SU-2026:3515-1: important: Security update for openssl-1_1 Message-ID: <178603414228.242.11911511292135748966@70aaff0f9d46> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:3515-1 Release Date: 2026-08-06T11:09:04Z Rating: important References: * bsc#1271712 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issue * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3515=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3515=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3515=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * openssl-1_1-1.1.1w-150600.5.35.2 * openssl-1_1-debugsource-1.1.1w-150600.5.35.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.35.2 * libopenssl1_1-debuginfo-1.1.1w-150600.5.35.2 * libopenssl-1_1-devel-1.1.1w-150600.5.35.2 * libopenssl1_1-1.1.1w-150600.5.35.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.35.2 * libopenssl1_1-32bit-1.1.1w-150600.5.35.2 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * openssl-1_1-1.1.1w-150600.5.35.2 * openssl-1_1-debugsource-1.1.1w-150600.5.35.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.35.2 * libopenssl1_1-debuginfo-1.1.1w-150600.5.35.2 * libopenssl-1_1-devel-1.1.1w-150600.5.35.2 * libopenssl1_1-1.1.1w-150600.5.35.2 * openSUSE Leap 15.6 (noarch) * openssl-1_1-doc-1.1.1w-150600.5.35.2 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl1_1-64bit-debuginfo-1.1.1w-150600.5.35.2 * libopenssl1_1-64bit-1.1.1w-150600.5.35.2 * libopenssl-1_1-devel-64bit-1.1.1w-150600.5.35.2 * openSUSE Leap 15.6 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.35.2 * libopenssl-1_1-devel-32bit-1.1.1w-150600.5.35.2 * libopenssl1_1-32bit-1.1.1w-150600.5.35.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * openssl-1_1-1.1.1w-150600.5.35.2 * openssl-1_1-debugsource-1.1.1w-150600.5.35.2 * libopenssl1_1-debuginfo-1.1.1w-150600.5.35.2 * openssl-1_1-debuginfo-1.1.1w-150600.5.35.2 * libopenssl-1_1-devel-1.1.1w-150600.5.35.2 * libopenssl1_1-1.1.1w-150600.5.35.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150600.5.35.2 * libopenssl1_1-32bit-1.1.1w-150600.5.35.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 12:31:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 12:31:28 -0000 Subject: SUSE-SU-2026:22999-1: moderate: Security update for sssd Message-ID: <178610588862.1051.9672129673398850942@1585592291d2> # Security update for sssd Announcement ID: SUSE-SU-2026:22999-1 Release Date: 2026-07-31T13:11:45Z Rating: moderate References: * bsc#1269807 Cross-References: * CVE-2026-12610 CVSS scores: * CVE-2026-12610 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12610 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12610 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for sssd fixes the following issue: * CVE-2026-12610: cancelled or completed PAM request while the asynchronous child process is still running can lead to a use-after-free (bsc#1269807). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1419=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * sssd-krb5-2.10.2-160000.4.1 * sssd-krb5-common-debuginfo-2.10.2-160000.4.1 * sssd-dbus-debuginfo-2.10.2-160000.4.1 * python3-sssd-config-debuginfo-2.10.2-160000.4.1 * libsss_idmap0-2.10.2-160000.4.1 * libsss_idmap0-debuginfo-2.10.2-160000.4.1 * sssd-ldap-2.10.2-160000.4.1 * sssd-tools-debuginfo-2.10.2-160000.4.1 * python3-sssd-config-2.10.2-160000.4.1 * libsss_certmap0-debuginfo-2.10.2-160000.4.1 * sssd-krb5-common-2.10.2-160000.4.1 * sssd-ad-debuginfo-2.10.2-160000.4.1 * sssd-ad-2.10.2-160000.4.1 * sssd-krb5-debuginfo-2.10.2-160000.4.1 * libsss_certmap0-2.10.2-160000.4.1 * sssd-debugsource-2.10.2-160000.4.1 * sssd-ldap-debuginfo-2.10.2-160000.4.1 * sssd-dbus-2.10.2-160000.4.1 * sssd-debuginfo-2.10.2-160000.4.1 * sssd-tools-2.10.2-160000.4.1 * sssd-2.10.2-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12610.html * https://bugzilla.suse.com/show_bug.cgi?id=1269807 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 12:32:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 12:32:41 -0000 Subject: SUSE-SU-2026:22997-1: moderate: Security update for hawk-apiserver Message-ID: <178610596162.1051.7899428365183988347@1585592291d2> # Security update for hawk-apiserver Announcement ID: SUSE-SU-2026:22997-1 Release Date: 2026-07-28T08:33:36Z Rating: moderate References: * bsc#1237259 * bsc#1248563 * bsc#1267454 Cross-References: * CVE-2022-28948 CVSS scores: * CVE-2022-28948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2022-28948 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 An update that solves one vulnerability and has two fixes can now be installed. ## Description: This update for hawk-apiserver fixes the following issues: Changes in hawk-apiserver: * Bump ClusterLabs/go-pacemaker v0.0.0-20260609131737-256130b189e0 (bsc#1267454) Version 0.1.0+git.1773234993.db3c82f: * handle /cib/live/primitives//edit in hawk-apiserver * Bump github.com/stretchr/testify.v1.11.0 and gopkg.in/yaml.v3.0.1 (bsc#1248563 CVE-2022-28948) * Dev: use the newest go-pacemaker and updated ToString (bsc#1237259) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1357=1 ## Package List: * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * hawk-apiserver-0.1.0+git.1781014483.1c464f2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2022-28948.html * https://bugzilla.suse.com/show_bug.cgi?id=1237259 * https://bugzilla.suse.com/show_bug.cgi?id=1248563 * https://bugzilla.suse.com/show_bug.cgi?id=1267454 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 20:31:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 20:31:49 -0000 Subject: SUSE-SU-2026:3530-1: important: Security update for python310 Message-ID: <178613470928.27003.820297597532051713@de6f93cd39e4> # Security update for python310 Announcement ID: SUSE-SU-2026:3530-1 Release Date: 2026-08-07T14:30:12Z Rating: important References: * bsc#1211301 * bsc#1264962 * bsc#1265268 * bsc#1267581 * bsc#1267821 * bsc#1268375 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1271192 Cross-References: * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-15308 * CVE-2026-3276 * CVE-2026-4360 * CVE-2026-7210 * CVE-2026-7774 * CVE-2026-8328 CVSS scores: * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves nine vulnerabilities and has two security fixes can now be installed. ## Description: This update for python310 fixes the following issues: Security issues fixed: * CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). * CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). * CVE-2026-4360: in the `Tarfile.extract()` function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). * CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). * CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). * CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server- supplied PASV host address (bsc#1265268). * CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). * CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). * CVE-2026-15308: incremental `HTMLParser` allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issues fixed: * Improve testing for the support of `IPPROTO_UDPLITE`, which could be not present although header files are (bsc#1268375). * Use the system-wide crypto-policies (bsc#1211301). * Support changes required for Sphinx 9. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3530=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3530=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3530=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3530=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3530=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2 * python310-base-3.10.20-150400.4.115.2 * python310-debuginfo-3.10.20-150400.4.115.1 * python310-core-debugsource-3.10.20-150400.4.115.2 * python310-3.10.20-150400.4.115.1 * python310-curses-debuginfo-3.10.20-150400.4.115.1 * python310-tools-3.10.20-150400.4.115.2 * libpython3_10-1_0-3.10.20-150400.4.115.2 * python310-tk-debuginfo-3.10.20-150400.4.115.1 * python310-idle-3.10.20-150400.4.115.1 * python310-debugsource-3.10.20-150400.4.115.1 * python310-curses-3.10.20-150400.4.115.1 * python310-tk-3.10.20-150400.4.115.1 * python310-dbm-3.10.20-150400.4.115.1 * python310-dbm-debuginfo-3.10.20-150400.4.115.1 * python310-base-debuginfo-3.10.20-150400.4.115.2 * python310-devel-3.10.20-150400.4.115.2 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python310-doc-3.10.20-150400.4.115.1 * python310-testsuite-debuginfo-3.10.20-150400.4.115.2 * python310-debuginfo-3.10.20-150400.4.115.1 * python310-tools-3.10.20-150400.4.115.2 * python310-dbm-debuginfo-3.10.20-150400.4.115.1 * python310-devel-3.10.20-150400.4.115.2 * python310-base-debuginfo-3.10.20-150400.4.115.2 * python310-curses-debuginfo-3.10.20-150400.4.115.1 * python310-debugsource-3.10.20-150400.4.115.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2 * python310-3.10.20-150400.4.115.1 * python310-tk-3.10.20-150400.4.115.1 * libpython3_10-1_0-3.10.20-150400.4.115.2 * python310-base-3.10.20-150400.4.115.2 * python310-core-debugsource-3.10.20-150400.4.115.2 * python310-tk-debuginfo-3.10.20-150400.4.115.1 * python310-idle-3.10.20-150400.4.115.1 * python310-curses-3.10.20-150400.4.115.1 * python310-dbm-3.10.20-150400.4.115.1 * python310-doc-devhelp-3.10.20-150400.4.115.1 * python310-testsuite-3.10.20-150400.4.115.2 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-debuginfo-3.10.20-150400.4.115.2 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.115.2 * libpython3_10-1_0-32bit-3.10.20-150400.4.115.2 * python310-base-32bit-3.10.20-150400.4.115.2 * python310-32bit-debuginfo-3.10.20-150400.4.115.1 * python310-32bit-3.10.20-150400.4.115.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_10-1_0-64bit-debuginfo-3.10.20-150400.4.115.2 * python310-base-64bit-debuginfo-3.10.20-150400.4.115.2 * python310-64bit-3.10.20-150400.4.115.1 * libpython3_10-1_0-64bit-3.10.20-150400.4.115.2 * python310-base-64bit-3.10.20-150400.4.115.2 * python310-64bit-debuginfo-3.10.20-150400.4.115.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2 * python310-base-3.10.20-150400.4.115.2 * python310-curses-debuginfo-3.10.20-150400.4.115.1 * python310-core-debugsource-3.10.20-150400.4.115.2 * python310-3.10.20-150400.4.115.1 * python310-debuginfo-3.10.20-150400.4.115.1 * python310-base-debuginfo-3.10.20-150400.4.115.2 * python310-tools-3.10.20-150400.4.115.2 * python310-tk-debuginfo-3.10.20-150400.4.115.1 * python310-idle-3.10.20-150400.4.115.1 * python310-debugsource-3.10.20-150400.4.115.1 * python310-curses-3.10.20-150400.4.115.1 * python310-tk-3.10.20-150400.4.115.1 * python310-dbm-3.10.20-150400.4.115.1 * python310-dbm-debuginfo-3.10.20-150400.4.115.1 * python310-devel-3.10.20-150400.4.115.2 * libpython3_10-1_0-3.10.20-150400.4.115.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2 * python310-base-3.10.20-150400.4.115.2 * python310-3.10.20-150400.4.115.1 * python310-debuginfo-3.10.20-150400.4.115.1 * python310-core-debugsource-3.10.20-150400.4.115.2 * python310-curses-debuginfo-3.10.20-150400.4.115.1 * python310-tools-3.10.20-150400.4.115.2 * python310-tk-debuginfo-3.10.20-150400.4.115.1 * python310-idle-3.10.20-150400.4.115.1 * python310-devel-3.10.20-150400.4.115.2 * python310-debugsource-3.10.20-150400.4.115.1 * python310-curses-3.10.20-150400.4.115.1 * python310-tk-3.10.20-150400.4.115.1 * python310-dbm-3.10.20-150400.4.115.1 * python310-dbm-debuginfo-3.10.20-150400.4.115.1 * python310-base-debuginfo-3.10.20-150400.4.115.2 * libpython3_10-1_0-3.10.20-150400.4.115.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python310-3.10.20-150400.4.115.1 * python310-debuginfo-3.10.20-150400.4.115.1 * python310-base-3.10.20-150400.4.115.2 * python310-core-debugsource-3.10.20-150400.4.115.2 * python310-base-debuginfo-3.10.20-150400.4.115.2 * python310-curses-debuginfo-3.10.20-150400.4.115.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.115.2 * python310-tools-3.10.20-150400.4.115.2 * python310-tk-debuginfo-3.10.20-150400.4.115.1 * python310-idle-3.10.20-150400.4.115.1 * python310-debugsource-3.10.20-150400.4.115.1 * python310-curses-3.10.20-150400.4.115.1 * python310-tk-3.10.20-150400.4.115.1 * python310-dbm-3.10.20-150400.4.115.1 * python310-dbm-debuginfo-3.10.20-150400.4.115.1 * python310-devel-3.10.20-150400.4.115.2 * libpython3_10-1_0-3.10.20-150400.4.115.2 ## References: * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://bugzilla.suse.com/show_bug.cgi?id=1211301 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1268375 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 20:32:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 20:32:54 -0000 Subject: SUSE-SU-2026:3529-1: important: Security update for ffmpeg-4 Message-ID: <178613477408.27003.11339559759615985971@de6f93cd39e4> # Security update for ffmpeg-4 Announcement ID: SUSE-SU-2026:3529-1 Release Date: 2026-08-07T14:23:26Z Rating: important References: * bsc#1268595 * bsc#1269490 * bsc#1272752 * bsc#1272754 * bsc#1272758 * bsc#1272765 * bsc#1272768 Cross-References: * CVE-2026-12706 * CVE-2026-64830 * CVE-2026-64832 * CVE-2026-64835 * CVE-2026-66038 * CVE-2026-66039 * CVE-2026-8461 CVSS scores: * CVE-2026-12706 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12706 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64830 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64830 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64830 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64830 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64832 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64832 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64832 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64832 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64835 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64835 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64835 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64835 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66038 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-66038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-66038 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66038 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-66038 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-66039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66039 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-66039 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66039 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66039 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8461 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8461 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-8461 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves seven vulnerabilities can now be installed. ## Description: This update for ffmpeg-4 fixes the following issues: Update to release 4.4.8. * CVE-2026-8461: out-of-bounds write in the MagicYUV decoder can lead to denial of service or remote code execution (bsc#1269490). * CVE-2026-12706: heap use-after-free read in the RASC video decoder can lead to denial of service (bsc#1268595). * CVE-2026-64830: heap buffer overflow in the VobSub subtitle demuxer can lead to arbitrary code execution (bsc#1272752). * CVE-2026-64832: double-free in the NVIDIA NVDEC hardware decoder can lead to can lead to memory corruption (bsc#1272754). * CVE-2026-64835: out-of-bounds memory access in the ADX audio decoder can lead to information disclosure and memory corruption (bsc#1272758). * CVE-2026-66038: exposure of uninitialized heap memory by the LCL/ZLIB video decoder can lead to sensitive information disclosure (bsc#1272768). * CVE-2026-66039: signed integer overflow in the MACE6 audio decoder can lead to heap corruption and arbitrary code execution (bsc#1272765). Other updates and bugfixes: * Release 4.4.8 * Various bug fixes to codecs * avcodec/magicyuv: Fix 1 line MEDIAN slices * avcodec/magicyuv: Expand the `s->interlaced` slice-height sanity check * avcodec/magicyuv: reject `slice_height` misaligned with chroma vshift * Address build failure on s390x. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3529=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3529=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3529=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3529=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3529=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libswscale5_9-debuginfo-4.4.8-150400.3.72.1 * libswresample3_9-4.4.8-150400.3.72.1 * ffmpeg-4-libavutil-devel-4.4.8-150400.3.72.1 * ffmpeg-4-4.4.8-150400.3.72.1 * libpostproc55_9-4.4.8-150400.3.72.1 * ffmpeg-4-libavdevice-devel-4.4.8-150400.3.72.1 * ffmpeg-4-libavfilter-devel-4.4.8-150400.3.72.1 * libavdevice58_13-4.4.8-150400.3.72.1 * libavfilter7_110-4.4.8-150400.3.72.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.72.1 * ffmpeg-4-libswresample-devel-4.4.8-150400.3.72.1 * libavformat58_76-debuginfo-4.4.8-150400.3.72.1 * ffmpeg-4-libavcodec-devel-4.4.8-150400.3.72.1 * libavfilter7_110-debuginfo-4.4.8-150400.3.72.1 * ffmpeg-4-debugsource-4.4.8-150400.3.72.1 * ffmpeg-4-libavresample-devel-4.4.8-150400.3.72.1 * ffmpeg-4-libavformat-devel-4.4.8-150400.3.72.1 * ffmpeg-4-libpostproc-devel-4.4.8-150400.3.72.1 * libavcodec58_134-4.4.8-150400.3.72.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.72.1 * libavresample4_0-4.4.8-150400.3.72.1 * libavresample4_0-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-debuginfo-4.4.8-150400.3.72.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-4.4.8-150400.3.72.1 * ffmpeg-4-private-devel-4.4.8-150400.3.72.1 * ffmpeg-4-libswscale-devel-4.4.8-150400.3.72.1 * libavdevice58_13-debuginfo-4.4.8-150400.3.72.1 * libswresample3_9-debuginfo-4.4.8-150400.3.72.1 * libavformat58_76-4.4.8-150400.3.72.1 * libavutil56_70-4.4.8-150400.3.72.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libavresample4_0-64bit-4.4.8-150400.3.72.1 * libswresample3_9-64bit-debuginfo-4.4.8-150400.3.72.1 * libavdevice58_13-64bit-debuginfo-4.4.8-150400.3.72.1 * libavformat58_76-64bit-4.4.8-150400.3.72.1 * libavcodec58_134-64bit-4.4.8-150400.3.72.1 * libavformat58_76-64bit-debuginfo-4.4.8-150400.3.72.1 * libavfilter7_110-64bit-debuginfo-4.4.8-150400.3.72.1 * libswresample3_9-64bit-4.4.8-150400.3.72.1 * libavutil56_70-64bit-4.4.8-150400.3.72.1 * libpostproc55_9-64bit-4.4.8-150400.3.72.1 * libpostproc55_9-64bit-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-64bit-debuginfo-4.4.8-150400.3.72.1 * libavfilter7_110-64bit-4.4.8-150400.3.72.1 * libavdevice58_13-64bit-4.4.8-150400.3.72.1 * libswscale5_9-64bit-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-64bit-4.4.8-150400.3.72.1 * libavcodec58_134-64bit-debuginfo-4.4.8-150400.3.72.1 * libavresample4_0-64bit-debuginfo-4.4.8-150400.3.72.1 * openSUSE Leap 15.4 (x86_64) * libavcodec58_134-32bit-4.4.8-150400.3.72.1 * libswresample3_9-32bit-4.4.8-150400.3.72.1 * libswscale5_9-32bit-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-32bit-4.4.8-150400.3.72.1 * libavformat58_76-32bit-4.4.8-150400.3.72.1 * libavresample4_0-32bit-4.4.8-150400.3.72.1 * libavresample4_0-32bit-debuginfo-4.4.8-150400.3.72.1 * libswresample3_9-32bit-debuginfo-4.4.8-150400.3.72.1 * libavdevice58_13-32bit-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-32bit-debuginfo-4.4.8-150400.3.72.1 * libavfilter7_110-32bit-4.4.8-150400.3.72.1 * libpostproc55_9-32bit-4.4.8-150400.3.72.1 * libavfilter7_110-32bit-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-32bit-4.4.8-150400.3.72.1 * libavdevice58_13-32bit-4.4.8-150400.3.72.1 * libpostproc55_9-32bit-debuginfo-4.4.8-150400.3.72.1 * libavcodec58_134-32bit-debuginfo-4.4.8-150400.3.72.1 * libavformat58_76-32bit-debuginfo-4.4.8-150400.3.72.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libswresample3_9-4.4.8-150400.3.72.1 * libavformat58_76-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-debuginfo-4.4.8-150400.3.72.1 * libavformat58_76-4.4.8-150400.3.72.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.72.1 * ffmpeg-4-debugsource-4.4.8-150400.3.72.1 * libswresample3_9-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-4.4.8-150400.3.72.1 * libpostproc55_9-4.4.8-150400.3.72.1 * libavcodec58_134-4.4.8-150400.3.72.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.72.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-4.4.8-150400.3.72.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libswresample3_9-4.4.8-150400.3.72.1 * libavformat58_76-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-debuginfo-4.4.8-150400.3.72.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.72.1 * libavformat58_76-4.4.8-150400.3.72.1 * ffmpeg-4-debugsource-4.4.8-150400.3.72.1 * libswresample3_9-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-4.4.8-150400.3.72.1 * libpostproc55_9-4.4.8-150400.3.72.1 * libavcodec58_134-4.4.8-150400.3.72.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.72.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-4.4.8-150400.3.72.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libswresample3_9-4.4.8-150400.3.72.1 * libavformat58_76-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-debuginfo-4.4.8-150400.3.72.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.72.1 * libavformat58_76-4.4.8-150400.3.72.1 * ffmpeg-4-debugsource-4.4.8-150400.3.72.1 * libswresample3_9-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-4.4.8-150400.3.72.1 * libpostproc55_9-4.4.8-150400.3.72.1 * libavcodec58_134-4.4.8-150400.3.72.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.72.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-4.4.8-150400.3.72.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libswresample3_9-4.4.8-150400.3.72.1 * libavformat58_76-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-debuginfo-4.4.8-150400.3.72.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.72.1 * ffmpeg-4-debugsource-4.4.8-150400.3.72.1 * libswresample3_9-debuginfo-4.4.8-150400.3.72.1 * libavutil56_70-4.4.8-150400.3.72.1 * libpostproc55_9-4.4.8-150400.3.72.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.72.1 * libavcodec58_134-4.4.8-150400.3.72.1 * libavformat58_76-4.4.8-150400.3.72.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.72.1 * libswscale5_9-4.4.8-150400.3.72.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12706.html * https://www.suse.com/security/cve/CVE-2026-64830.html * https://www.suse.com/security/cve/CVE-2026-64832.html * https://www.suse.com/security/cve/CVE-2026-64835.html * https://www.suse.com/security/cve/CVE-2026-66038.html * https://www.suse.com/security/cve/CVE-2026-66039.html * https://www.suse.com/security/cve/CVE-2026-8461.html * https://bugzilla.suse.com/show_bug.cgi?id=1268595 * https://bugzilla.suse.com/show_bug.cgi?id=1269490 * https://bugzilla.suse.com/show_bug.cgi?id=1272752 * https://bugzilla.suse.com/show_bug.cgi?id=1272754 * https://bugzilla.suse.com/show_bug.cgi?id=1272758 * https://bugzilla.suse.com/show_bug.cgi?id=1272765 * https://bugzilla.suse.com/show_bug.cgi?id=1272768 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 20:33:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 20:33:51 -0000 Subject: SUSE-SU-2026:3528-1: important: Security update for azure-storage-azcopy Message-ID: <178613483189.27003.1308961178875490228@de6f93cd39e4> # Security update for azure-storage-azcopy Announcement ID: SUSE-SU-2026:3528-1 Release Date: 2026-08-07T14:20:23Z Rating: important References: * bsc#1266657 * bsc#1272123 Cross-References: * CVE-2026-39821 * CVE-2026-56852 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for azure-storage-azcopy fixes the following issues: Update to 10.32.6. Security issues fixed: * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266657). * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of truncated/invalid UTF-8 input can lead to infinite loop (bsc#1272123). Other updates and bugfixes: * Version 10.32.6: * Run `go mod tidy` * Merge tag `v10.32.4` into release/fips * Merge `remote-tracking` branch `origin/wendi/10.32.5` into `release/fips` * Merge branch `main` into `wendi/10.32.5` * TASK 38260338: Updated the release pipeline to produce Linux builds capable of complying with the FIPS 140-3 standard. (#3488) * Bump Go toolchain and security-relevant dependencies (#3486) * stylistic changes from copilot :) * Update `golang.org/x/text` to v0.40.0 * Update `golang.org/x/net` to v0.57.0 * Version 10.32.5: * Create new patch release * Merge branch `main` into `seanmcc/bump-deps-2026-06` * Ensure get/set ACLs are on URLs with paths (#3453) * Print out help command on just `azcopy` (#3485) * Bump Go toolchain and security-relevant dependencies * Centralize HTTP client into a shared global instance (#3436) * Remove 0-padding in mode with SetUID (#3467) * Updated `trivy` dependency to known safe version (#3421) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3528=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3528=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3528=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3528=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3528=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.6-150400.9.16.2 * Public Cloud Module 15-SP5 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.6-150400.9.16.2 * Public Cloud Module 15-SP4 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.6-150400.9.16.2 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.6-150400.9.16.2 * Public Cloud Module 15-SP6 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.6-150400.9.16.2 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1266657 * https://bugzilla.suse.com/show_bug.cgi?id=1272123 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 20:34:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 20:34:47 -0000 Subject: SUSE-SU-2026:3527-1: moderate: Security update for gstreamer-plugins-bad Message-ID: <178613488755.27003.515649945535384606@de6f93cd39e4> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:3527-1 Release Date: 2026-08-07T14:17:46Z Rating: moderate References: * bsc#1268394 Cross-References: * CVE-2026-52718 CVSS scores: * CVE-2026-52718 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-52718 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issue: * CVE-2026-52718: byte count instead of a bit count in gst_av1_parser_parse_tile_list_obu() can cause parser desynchronization and an application crash (bsc#1268394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3527=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3527=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3527=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3527=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstVulkanXCB-1_0-1.24.0-150600.4.12.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.12.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.12.1 * typelib-1_0-GstTranscoder-1_0-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-1.24.0-150600.4.12.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.12.1 * typelib-1_0-GstVulkan-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-chromaprint-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-1.24.0-150600.4.12.1 * libgstmse-1_0-0-1.24.0-150600.4.12.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstva-1_0-0-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.12.1 * libgstplay-1_0-0-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.12.1 * typelib-1_0-GstVulkanWayland-1_0-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-1.24.0-150600.4.12.1 * gstreamer-transcoder-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.12.1 * gstreamer-transcoder-debuginfo-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.12.1 * gstreamer-transcoder-devel-1.24.0-150600.4.12.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libgstphotography-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstmse-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstva-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-64bit-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstva-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstmse-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-64bit-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstplay-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-chromaprint-64bit-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstplay-1_0-0-64bit-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-64bit-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-64bit-1.24.0-150600.4.12.1 * openSUSE Leap 15.6 (x86_64) * libgstvulkan-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-chromaprint-32bit-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstmse-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstva-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstva-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstplay-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstplay-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-32bit-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-32bit-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-32bit-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-32bit-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-32bit-debuginfo-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-32bit-1.24.0-150600.4.12.1 * libgstmse-1_0-0-32bit-1.24.0-150600.4.12.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.12.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.12.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.12.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-1.24.0-150600.4.12.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstmse-1_0-0-1.24.0-150600.4.12.1 * libgstisoff-1_0-0-1.24.0-150600.4.12.1 * libgstva-1_0-0-1.24.0-150600.4.12.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.12.1 * libgstvulkan-1_0-0-1.24.0-150600.4.12.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.12.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstcodecs-1_0-0-1.24.0-150600.4.12.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.12.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-1.24.0-150600.4.12.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.12.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.12.1 * libgstwayland-1_0-0-1.24.0-150600.4.12.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.12.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.12.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.12.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.12.1 * Desktop Applications Module 15-SP7 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.12.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.12.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstphotography-1_0-0-1.24.0-150600.4.12.1 * libgstplay-1_0-0-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.12.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.12.1 * libgstplayer-1_0-0-1.24.0-150600.4.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52718.html * https://bugzilla.suse.com/show_bug.cgi?id=1268394 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 20:35:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 20:35:52 -0000 Subject: SUSE-SU-2026:3526-1: important: Security update for libssh2_org Message-ID: <178613495288.27003.14830254699958598119@de6f93cd39e4> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3526-1 Release Date: 2026-08-07T13:09:58Z Rating: important References: * bsc#1263890 * bsc#1268546 * bsc#1269567 * bsc#1269568 * bsc#1272734 * bsc#1272735 * bsc#1272736 * bsc#1272737 Cross-References: * CVE-2025-15661 * CVE-2026-58050 * CVE-2026-58051 * CVE-2026-66032 * CVE-2026-66033 * CVE-2026-66034 * CVE-2026-66035 * CVE-2026-7598 CVSS scores: * CVE-2025-15661 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2025-15661 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15661 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-15661 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58050 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58050 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58050 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58050 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58050 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58051 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58051 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58051 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58051 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-66032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66032 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66032 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66032 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66033 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66033 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66033 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66033 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66034 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66034 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66034 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66034 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66035 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66035 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66035 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66035 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-7598 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7598 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7598 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for libssh2_org fixes the following issues: * CVE-2025-15661: out-of-bounds heap read vulnerability in the `sftp_symlink()` function in `src/sftp.c` (bsc#1268546). * CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890). * CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response (bsc#1269568). * CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567). * CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737). * CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736). * CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735). * CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3526=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3526=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3526=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3526=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3526=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3526=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3526=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3526=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3526=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3526=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3526=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3526=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3526=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libssh2_org-debugsource-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libssh2-1-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libssh2_org-debugsource-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libssh2_org-debugsource-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libssh2-1-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libssh2-1-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.8.1 * libssh2_org-debugsource-1.11.0-150200.9.8.1 * libssh2-1-1.11.0-150200.9.8.1 * libssh2-devel-1.11.0-150200.9.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.8.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15661.html * https://www.suse.com/security/cve/CVE-2026-58050.html * https://www.suse.com/security/cve/CVE-2026-58051.html * https://www.suse.com/security/cve/CVE-2026-66032.html * https://www.suse.com/security/cve/CVE-2026-66033.html * https://www.suse.com/security/cve/CVE-2026-66034.html * https://www.suse.com/security/cve/CVE-2026-66035.html * https://www.suse.com/security/cve/CVE-2026-7598.html * https://bugzilla.suse.com/show_bug.cgi?id=1263890 * https://bugzilla.suse.com/show_bug.cgi?id=1268546 * https://bugzilla.suse.com/show_bug.cgi?id=1269567 * https://bugzilla.suse.com/show_bug.cgi?id=1269568 * https://bugzilla.suse.com/show_bug.cgi?id=1272734 * https://bugzilla.suse.com/show_bug.cgi?id=1272735 * https://bugzilla.suse.com/show_bug.cgi?id=1272736 * https://bugzilla.suse.com/show_bug.cgi?id=1272737 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Aug 7 20:36:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 07 Aug 2026 20:36:43 -0000 Subject: SUSE-SU-2026:3525-1: important: Security update for libssh2_org Message-ID: <178613500321.27003.3523513147102316504@de6f93cd39e4> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3525-1 Release Date: 2026-08-07T13:08:29Z Rating: important References: * bsc#1263890 * bsc#1268530 * bsc#1268546 * bsc#1269567 * bsc#1269568 * bsc#1272734 * bsc#1272735 * bsc#1272736 * bsc#1272737 Cross-References: * CVE-2025-15661 * CVE-2026-55199 * CVE-2026-58050 * CVE-2026-58051 * CVE-2026-66032 * CVE-2026-66033 * CVE-2026-66034 * CVE-2026-66035 * CVE-2026-7598 CVSS scores: * CVE-2025-15661 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2025-15661 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15661 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-15661 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58050 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58050 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58050 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58050 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58050 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58051 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58051 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58051 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58051 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-66032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66032 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66032 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66032 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66033 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66033 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66033 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66033 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66034 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66034 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66034 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66034 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66035 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66035 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66035 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66035 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-7598 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7598 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7598 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for libssh2_org fixes the following issues: * CVE-2025-15661: out-of-bounds heap read vulnerability in the `sftp_symlink()` function in `src/sftp.c` (bsc#1268546). * CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890). * CVE-2026-55199: pre-authentication DoS via the `SSH_MSG_EXT_INFO` handler (bsc#1268530). * CVE-2026-58050: heap buffer overflow due to missing bounds check in attribute count of publickey-subsystem response (bsc#1269568). * CVE-2026-58051: uninitialized pointer freed when malformed responses are sent by an SSH server (bsc#1269567). * CVE-2026-66032: arbitrary code execution via double-free in SFTP session (bsc#1272737). * CVE-2026-66033: denial of service via integer underflow in AES-GCM cipher negotiation (bsc#1272736). * CVE-2026-66034: information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735). * CVE-2026-66035: arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3525=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3525=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libssh2-1-debuginfo-1.11.0-29.18.1 * libssh2-devel-1.11.0-29.18.1 * libssh2-1-1.11.0-29.18.1 * libssh2_org-debugsource-1.11.0-29.18.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libssh2-1-debuginfo-32bit-1.11.0-29.18.1 * libssh2-1-32bit-1.11.0-29.18.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libssh2-1-32bit-1.11.0-29.18.1 * libssh2-devel-1.11.0-29.18.1 * libssh2-1-debuginfo-1.11.0-29.18.1 * libssh2-1-debuginfo-32bit-1.11.0-29.18.1 * libssh2-1-1.11.0-29.18.1 * libssh2_org-debugsource-1.11.0-29.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15661.html * https://www.suse.com/security/cve/CVE-2026-55199.html * https://www.suse.com/security/cve/CVE-2026-58050.html * https://www.suse.com/security/cve/CVE-2026-58051.html * https://www.suse.com/security/cve/CVE-2026-66032.html * https://www.suse.com/security/cve/CVE-2026-66033.html * https://www.suse.com/security/cve/CVE-2026-66034.html * https://www.suse.com/security/cve/CVE-2026-66035.html * https://www.suse.com/security/cve/CVE-2026-7598.html * https://bugzilla.suse.com/show_bug.cgi?id=1263890 * https://bugzilla.suse.com/show_bug.cgi?id=1268530 * https://bugzilla.suse.com/show_bug.cgi?id=1268546 * https://bugzilla.suse.com/show_bug.cgi?id=1269567 * https://bugzilla.suse.com/show_bug.cgi?id=1269568 * https://bugzilla.suse.com/show_bug.cgi?id=1272734 * https://bugzilla.suse.com/show_bug.cgi?id=1272735 * https://bugzilla.suse.com/show_bug.cgi?id=1272736 * https://bugzilla.suse.com/show_bug.cgi?id=1272737 -------------- next part -------------- An HTML attachment was scrubbed... URL: