From null at suse.de Wed Jul 1 08:30:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 08:30:09 -0000 Subject: SUSE-SU-2026:2716-1: important: Security update for pacemaker Message-ID: <178289460956.11796.11100753608875339967@b8d31ed95d57> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2716-1 Release Date: 2026-06-30T15:34:32Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issue * CVE-2026-10649: denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-2716=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2716=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debugsource-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-devel-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (noarch) * pacemaker-schemas-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cts-2.1.7+20231219.0f7f88312-150600.6.15.1 * python3-pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debugsource-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-devel-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cli-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-libs-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-remote-debuginfo-2.1.7+20231219.0f7f88312-150600.6.15.1 * openSUSE Leap 15.6 (noarch) * pacemaker-schemas-2.1.7+20231219.0f7f88312-150600.6.15.1 * pacemaker-cts-2.1.7+20231219.0f7f88312-150600.6.15.1 * python3-pacemaker-2.1.7+20231219.0f7f88312-150600.6.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 12:30:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 12:30:30 -0000 Subject: SUSE-SU-2026:2717-1: important: Security update for apache2 Message-ID: <178290903063.74.823081231680708374@f3f8e2fb38c1> # Security update for apache2 Announcement ID: SUSE-SU-2026:2717-1 Release Date: 2026-07-01T08:05:44Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2717=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2717=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * apache2-tls13-devel-2.4.66-35.81.1 * apache2-worker-2.4.66-35.81.1 * apache2-devel-2.4.66-35.81.1 * apache2-tls13-debugsource-2.4.66-35.81.1 * apache2-tls13-example-pages-2.4.66-35.81.1 * apache2-tls13-worker-debuginfo-2.4.66-35.81.1 * apache2-debugsource-2.4.66-35.81.1 * apache2-example-pages-2.4.66-35.81.1 * apache2-tls13-debuginfo-2.4.66-35.81.1 * apache2-worker-debuginfo-2.4.66-35.81.1 * apache2-tls13-utils-2.4.66-35.81.1 * apache2-tls13-prefork-2.4.66-35.81.1 * apache2-tls13-worker-2.4.66-35.81.1 * apache2-utils-debuginfo-2.4.66-35.81.1 * apache2-tls13-2.4.66-35.81.1 * apache2-utils-2.4.66-35.81.1 * apache2-prefork-2.4.66-35.81.1 * apache2-tls13-utils-debuginfo-2.4.66-35.81.1 * apache2-debuginfo-2.4.66-35.81.1 * apache2-tls13-prefork-debuginfo-2.4.66-35.81.1 * apache2-2.4.66-35.81.1 * apache2-prefork-debuginfo-2.4.66-35.81.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * apache2-tls13-doc-2.4.66-35.81.1 * apache2-doc-2.4.66-35.81.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-tls13-devel-2.4.66-35.81.1 * apache2-devel-2.4.66-35.81.1 * apache2-worker-2.4.66-35.81.1 * apache2-tls13-debugsource-2.4.66-35.81.1 * apache2-tls13-example-pages-2.4.66-35.81.1 * apache2-tls13-worker-debuginfo-2.4.66-35.81.1 * apache2-debugsource-2.4.66-35.81.1 * apache2-example-pages-2.4.66-35.81.1 * apache2-prefork-debuginfo-2.4.66-35.81.1 * apache2-tls13-debuginfo-2.4.66-35.81.1 * apache2-worker-debuginfo-2.4.66-35.81.1 * apache2-tls13-utils-2.4.66-35.81.1 * apache2-tls13-prefork-2.4.66-35.81.1 * apache2-tls13-worker-2.4.66-35.81.1 * apache2-utils-debuginfo-2.4.66-35.81.1 * apache2-tls13-2.4.66-35.81.1 * apache2-prefork-2.4.66-35.81.1 * apache2-tls13-utils-debuginfo-2.4.66-35.81.1 * apache2-debuginfo-2.4.66-35.81.1 * apache2-tls13-prefork-debuginfo-2.4.66-35.81.1 * apache2-2.4.66-35.81.1 * apache2-utils-2.4.66-35.81.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * apache2-tls13-doc-2.4.66-35.81.1 * apache2-doc-2.4.66-35.81.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:30:24 -0000 Subject: SUSE-SU-2026:22391-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178292342491.5373.17020023569244812545@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22391-1 Release Date: 2026-06-26T08:14:10Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1087=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1087=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_31-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_31-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_10-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_31-default-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:30:41 -0000 Subject: SUSE-SU-2026:22390-1: important: Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178292344140.5373.14363055261249300942@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22390-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1075=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1075=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_8-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-9-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_8-default-9-160000.1.1 * kernel-livepatch-6_12_0-160000_8-default-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16_Update_3-debugsource-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:30:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:30:58 -0000 Subject: SUSE-SU-2026:22389-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178292345828.5373.11559852252396422121@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22389-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1074=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1074=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_29-default-4-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-debuginfo-4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-4-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-debuginfo-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:31:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:31:13 -0000 Subject: SUSE-SU-2026:22388-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178292347318.5373.12045563289898977444@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22388-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1073=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1073=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_7-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_7-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_28-default-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:31:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:31:30 -0000 Subject: SUSE-SU-2026:22387-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178292349022.5373.8048321138801485450@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22387-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1072=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1072=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_6-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_6-debugsource-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-6-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-debuginfo-6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:31:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:31:46 -0000 Subject: SUSE-SU-2026:22386-1: important: Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178292350689.5373.7266697321102005754@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22386-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1071=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1071=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-8-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-8-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_9-default-debuginfo-8-160000.1.1 * kernel-livepatch-SLE16_Update_4-debugsource-8-160000.1.1 * kernel-livepatch-6_12_0-160000_9-default-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:32:03 -0000 Subject: SUSE-SU-2026:22385-1: important: Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178292352302.5373.12792641556973140595@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22385-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1070=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1070=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_2-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-10-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_7-default-10-160000.1.1 * kernel-livepatch-SLE16_Update_2-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_7-default-debuginfo-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:32:21 -0000 Subject: SUSE-SU-2026:22384-1: important: Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178292354161.5373.8057096408915407378@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22384-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1069=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1069=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_6-default-debuginfo-12-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-12-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-12-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_6-default-debuginfo-12-160000.1.1 * kernel-livepatch-6_12_0-160000_6-default-12-160000.1.1 * kernel-livepatch-SLE16_Update_1-debugsource-12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:32:37 -0000 Subject: SUSE-SU-2026:22383-1: important: Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178292355734.5373.11071463570884190200@bea6e15a6baf> # Security update for the Linux Kernel (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22383-1 Release Date: 2026-06-25T11:19:45Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1068=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1068=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_5-default-debuginfo-14-160000.4.3 * kernel-livepatch-SLE16_Update_0-debugsource-14-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-14-160000.4.3 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_0-debugsource-14-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-14-160000.4.3 * kernel-livepatch-6_12_0-160000_5-default-debuginfo-14-160000.4.3 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:32:43 -0000 Subject: SUSE-SU-2026:22382-1: important: Security update for giflib Message-ID: <178292356390.5373.14927308625350445277@bea6e15a6baf> # Security update for giflib Announcement ID: SUSE-SU-2026:22382-1 Release Date: 2026-06-28T09:26:36Z Rating: important References: * bsc#1259836 Cross-References: * CVE-2026-26740 CVSS scores: * CVE-2026-26740 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-26740 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-26740 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-26740 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for giflib fixes the following issue * CVE-2026-26740: heap out-of-bounds read when processing a specially crafted GIF file containing a GCE block with a truncated extension byte count (bsc#1259836). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1098=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1098=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * giflib-devel-5.2.2-160000.4.1 * giflib-progs-5.2.2-160000.4.1 * giflib-progs-debuginfo-5.2.2-160000.4.1 * giflib-debugsource-5.2.2-160000.4.1 * libgif7-debuginfo-5.2.2-160000.4.1 * libgif7-5.2.2-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * giflib-devel-5.2.2-160000.4.1 * giflib-progs-5.2.2-160000.4.1 * giflib-debugsource-5.2.2-160000.4.1 * giflib-progs-debuginfo-5.2.2-160000.4.1 * libgif7-debuginfo-5.2.2-160000.4.1 * libgif7-5.2.2-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-26740.html * https://bugzilla.suse.com/show_bug.cgi?id=1259836 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:32:49 -0000 Subject: SUSE-SU-2026:22381-1: moderate: Security update for alsa Message-ID: <178292356949.5373.5939264697584170311@bea6e15a6baf> # Security update for alsa Announcement ID: SUSE-SU-2026:22381-1 Release Date: 2026-06-28T08:50:00Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1097=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1097=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libatopology2-1.2.14-160000.3.1 * libasound2-1.2.14-160000.3.1 * alsa-topology-devel-1.2.14-160000.3.1 * libasound2-debuginfo-1.2.14-160000.3.1 * libatopology2-debuginfo-1.2.14-160000.3.1 * alsa-devel-1.2.14-160000.3.1 * alsa-debugsource-1.2.14-160000.3.1 * alsa-1.2.14-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * alsa-docs-1.2.14-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libasound2-1.2.14-160000.3.1 * libasound2-debuginfo-1.2.14-160000.3.1 * alsa-devel-1.2.14-160000.3.1 * alsa-debugsource-1.2.14-160000.3.1 * alsa-1.2.14-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * alsa-topology-devel-1.2.14-160000.3.1 * libatopology2-1.2.14-160000.3.1 * libatopology2-debuginfo-1.2.14-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * alsa-docs-1.2.14-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:32:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:32:55 -0000 Subject: SUSE-SU-2026:22380-1: low: Security update for loupe Message-ID: <178292357520.5373.3481892595029359901@bea6e15a6baf> # Security update for loupe Announcement ID: SUSE-SU-2026:22380-1 Release Date: 2026-06-28T08:41:36Z Rating: low References: * bsc#1249009 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for loupe fixes the following issue * CVE-2025-58160: tracing-subscriber: untrusted input containing ANSI escape sequences can lead to terminal manipulation (bsc#1249009). Changes for loupe: * Update to version 48.2: * Check if the is-hidden property is available before reading it. * Considerably increased speed for listing other images in folders, especially for remote locations. This allows for switching to other images to become available much quicker. * Fix panics, probably occuring when using an action like 'copy', and then closing the window. The crash causes all other windows to close. * The creation date for images that don't provide a timezone was displayed as if the recorded date and time was in UTC. * Zooming in would not work via the zoom menu, if the resulting zoom state would still fit the image inside the window. * Update to version 48.1: * Crash when closing the window, probably in the exact moment when the animnation for hiding controls starts. * Editing does not work correctly if PNGs or JPEGs are already rotated via an Exif orientation entry before editing. * Printed pages don't contain anything or garbled output. This is a temporary workaround for , using the cairo renderer for the rotation and scaling of the image in the print preparation. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1096=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1096=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * loupe-debugsource-48.2-160000.1.1 * loupe-debuginfo-48.2-160000.1.1 * loupe-48.2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * loupe-lang-48.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * loupe-debugsource-48.2-160000.1.1 * loupe-debuginfo-48.2-160000.1.1 * loupe-48.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * loupe-lang-48.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249009 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:33:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:33:53 -0000 Subject: SUSE-SU-2026:22378-1: important: Security update for ImageMagick Message-ID: <178292363350.5373.12406601021194444219@bea6e15a6baf> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:22378-1 Release Date: 2026-06-26T09:13:30Z Rating: important References: * bsc#1265048 * bsc#1265373 * bsc#1268092 * bsc#1268094 * bsc#1268095 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268103 * bsc#1268105 * bsc#1268107 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268116 * bsc#1268117 * bsc#1268119 * bsc#1268120 * bsc#1268121 * bsc#1268122 * bsc#1268123 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268645 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 Cross-References: * CVE-2026-40169 * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45359 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46557 * CVE-2026-46559 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48724 * CVE-2026-48733 * CVE-2026-48734 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53461 * CVE-2026-53463 * CVE-2026-53464 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56376 CVSS scores: * CVE-2026-40169 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40169 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45359 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45359 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46557 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46559 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46559 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-46559 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48724 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48724 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48724 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48733 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48733 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48733 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48734 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53461 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53464 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53464 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53464 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 0.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 0.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 32 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues Security issues: * CVE-2026-42050: Stack buffer overflow in XTileImage (bsc#1265048). * CVE-2026-42326: Information disclosure via malicious IPTC input file (bsc#1268092). * CVE-2026-45031: Denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). * CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). * CVE-2026-45359: Information Disclosure via Invalid Connected-Components Value (bsc#1268095). * CVE-2026-45624: Data exposure due to image processing vulnerability (bsc#1268096). * CVE-2026-45664: Denial of Service due to excessive resource use in MNG coder (bsc#1268101). * CVE-2026-46520: Denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). * CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). * CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). * CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123). * CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). * CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48724: Heap Buffer Underwrite in Floyd-Steinberg depth dithering (bsc#1268116). * CVE-2026-48733: Infinite Loop in subimage-search with crafted image (bsc#1268119). * CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). * CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). * CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). * CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). * CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107). * CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). * CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). * CVE-2026-56367: ImageMagick contains an integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out- of-bounds read (bsc#1268645). * CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). Non security issue: * ImageMagick update 7.1.2.0-160000.9.1 is broken for softlinks (bsc#1265373). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1093=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1093=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * ImageMagick-config-7-SUSE-7.1.2.0-160000.10.1 * ImageMagick-doc-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.10.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libMagick++-7_Q16HDRI5-7.1.2.0-160000.10.1 * libMagick++-devel-7.1.2.0-160000.10.1 * ImageMagick-devel-7.1.2.0-160000.10.1 * ImageMagick-extra-7.1.2.0-160000.10.1 * ImageMagick-7.1.2.0-160000.10.1 * perl-PerlMagick-7.1.2.0-160000.10.1 * ImageMagick-debugsource-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.10.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-debuginfo-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.10.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libMagick++-7_Q16HDRI5-7.1.2.0-160000.10.1 * libMagick++-devel-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-extra-7.1.2.0-160000.10.1 * ImageMagick-devel-7.1.2.0-160000.10.1 * perl-PerlMagick-7.1.2.0-160000.10.1 * ImageMagick-debugsource-7.1.2.0-160000.10.1 * ImageMagick-7.1.2.0-160000.10.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.10.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.10.1 * ImageMagick-debuginfo-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.10.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.10.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.10.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ImageMagick-config-7-SUSE-7.1.2.0-160000.10.1 * ImageMagick-doc-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.10.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40169.html * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45359.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46557.html * https://www.suse.com/security/cve/CVE-2026-46559.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48724.html * https://www.suse.com/security/cve/CVE-2026-48733.html * https://www.suse.com/security/cve/CVE-2026-48734.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53461.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53464.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1265373 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268095 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268103 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268107 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268116 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268119 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268121 * https://bugzilla.suse.com/show_bug.cgi?id=1268122 * https://bugzilla.suse.com/show_bug.cgi?id=1268123 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:34:03 -0000 Subject: SUSE-SU-2026:22377-1: important: Security update for tar Message-ID: <178292364357.5373.16795951432612812345@bea6e15a6baf> # Security update for tar Announcement ID: SUSE-SU-2026:22377-1 Release Date: 2026-06-26T09:13:30Z Rating: important References: * bsc#1261900 * bsc#1265450 * bsc#1267189 Cross-References: * CVE-2025-45582 * CVE-2026-5704 CVSS scores: * CVE-2025-45582 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-45582 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-45582 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:L * CVE-2026-5704 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-5704 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-5704 ( NVD ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-5704 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for tar fixes the following issues * CVE-2026-5704: crafted archives can be used to to hide file injection (bsc#1261900). * Fix --dereference/-h not working properly after CVE-2025-45582 fix (bsc#1265450). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1092=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1092=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * tar-debugsource-1.35-160000.4.1 * tar-rmt-debuginfo-1.35-160000.4.1 * tar-debuginfo-1.35-160000.4.1 * tar-1.35-160000.4.1 * tar-rmt-1.35-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tar-backup-scripts-1.35-160000.4.1 * tar-lang-1.35-160000.4.1 * tar-doc-1.35-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tar-backup-scripts-1.35-160000.4.1 * tar-lang-1.35-160000.4.1 * tar-doc-1.35-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * tar-debugsource-1.35-160000.4.1 * tar-rmt-debuginfo-1.35-160000.4.1 * tar-debuginfo-1.35-160000.4.1 * tar-1.35-160000.4.1 * tar-rmt-1.35-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-45582.html * https://www.suse.com/security/cve/CVE-2026-5704.html * https://bugzilla.suse.com/show_bug.cgi?id=1261900 * https://bugzilla.suse.com/show_bug.cgi?id=1265450 * https://bugzilla.suse.com/show_bug.cgi?id=1267189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:34:15 -0000 Subject: SUSE-SU-2026:22376-1: important: Security update for google-guest-agent Message-ID: <178292365558.5373.4273068937685779489@bea6e15a6baf> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:22376-1 Release Date: 2026-06-26T08:17:18Z Rating: important References: * bsc#1243254 * bsc#1243505 * bsc#1260264 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). Changes for google-guest-agent: * Update to version 20260529.00 * Dependency updates (#616) * from version 20260522.00 * Fix improper umask calculation on socket creation (#614) * from version 20260520.01 * Update OWNERS (#609) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Update to version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1091=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1091=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-guest-agent-20260529.00-160000.1.1 * google-guest-agent-debuginfo-20260529.00-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-guest-agent-20260529.00-160000.1.1 * google-guest-agent-debuginfo-20260529.00-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:34:31 -0000 Subject: SUSE-SU-2026:22373-1: important: Security update for python-tornado6 Message-ID: <178292367152.5373.13995939148497777875@bea6e15a6baf> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22373-1 Release Date: 2026-06-26T08:00:10Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1089=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1089=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-tornado6-6.5-160000.5.1 * python-tornado6-debugsource-6.5-160000.5.1 * python313-tornado6-debuginfo-6.5-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-tornado6-6.5-160000.5.1 * python-tornado6-debugsource-6.5-160000.5.1 * python313-tornado6-debuginfo-6.5-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:34:41 -0000 Subject: SUSE-SU-2026:22372-1: important: Security update for python-python-multipart Message-ID: <178292368126.5373.16593121935281790397@bea6e15a6baf> # Security update for python-python-multipart Announcement ID: SUSE-SU-2026:22372-1 Release Date: 2026-06-26T08:00:10Z Rating: important References: * bsc#1268488 * bsc#1268496 * bsc#1268500 * bsc#1268506 Cross-References: * CVE-2026-53537 * CVE-2026-53538 * CVE-2026-53539 * CVE-2026-53540 CVSS scores: * CVE-2026-53537 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53537 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53537 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53537 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53538 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53538 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53538 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-53539 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53539 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53539 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53540 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53540 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53540 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-python-multipart fixes the following issues * CVE-2026-53537: multipart/form-data with extended parameters can lead to file or parameter smuggling (bsc#1268506). * CVE-2026-53538: urlencoded requests containing semicolons can lead to form field smuggling (bsc#1268496). * CVE-2026-53539: small crafted body can cause a denial of service (bsc#1268500). * CVE-2026-53540: crafted request buffers can lead to degrading availability (bsc#1268488). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1088=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1088=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-python-multipart-0.0.20-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-python-multipart-0.0.20-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53537.html * https://www.suse.com/security/cve/CVE-2026-53538.html * https://www.suse.com/security/cve/CVE-2026-53539.html * https://www.suse.com/security/cve/CVE-2026-53540.html * https://bugzilla.suse.com/show_bug.cgi?id=1268488 * https://bugzilla.suse.com/show_bug.cgi?id=1268496 * https://bugzilla.suse.com/show_bug.cgi?id=1268500 * https://bugzilla.suse.com/show_bug.cgi?id=1268506 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:34:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:34:59 -0000 Subject: SUSE-SU-2026:22370-1: important: Security update for python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve Message-ID: <178292369957.5373.13677660573886822955@bea6e15a6baf> # Security update for python-Markdown, python-joblib, python-handy-archives, python-apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve Announcement ID: SUSE-SU-2026:22370-1 Release Date: 2026-06-26T07:41:13Z Rating: important References: * bsc#1256310 * bsc#1256316 * bsc#1258223 * bsc#1261918 * bsc#1263802 * bsc#1268243 * bsc#1268324 Cross-References: * CVE-2026-44889 CVSS scores: * CVE-2026-44889 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-44889 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44889 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and has six fixes can now be installed. ## Description: This update for python-Markdown, python-joblib, python-handy-archives, python- apache-libcloud, python-WebOb, python-PyGithub, python-soupsieve fixes the following issues: Changes in python-Markdown: * Fix tests with latest python version (bsc#1268243) Changes in python-joblib: * Update to 1.5.2: * fixing the resource tracker for python 3.13.7+ * Skip tests failing with Python 3.13.7 Changes in python-handy-archives: * Skip some zip64 tests that fails with latest python interpreter because there are more consistency checks in zipfile (bsc#1256310) Changes in python-apache-libcloud: * Fix tests compatibility with latest Python 3.13 (bsc#1258223, bsc#1261918) Changes in python-WebOb: * Security issues fixed: * CVE-2026-44889: Fixed: Location header normalization during redirect leads to open redirect (bsc#1268324) * Skip boken test with latest cpython interpreters (bsc#1258223) * Skip test failing on Python 3.14 Changes in python-PyGithub: * Fix: [SUSE:SLFO:Main] python-PyGithub fails to build on aarch64, ppc64le, s390x, x86_64 (bsc#1263802) Changes in python-soupsieve: * Fix: [SUSE:SLFO:Main] python-soupsieve:test fails to build on aarch64, ppc64le, s390x, x86_64 (bsc#1256316) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1084=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1084=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-apache-libcloud-3.8.0-160000.3.1 * python313-WebOb-1.8.9-160000.3.1 * python313-soupsieve-2.6-160000.3.1 * python313-PyGithub-2.6.1-160000.3.1 * python313-Markdown-3.8.2-160000.3.1 * python313-handy-archives-0.2.0-160000.3.1 * python-WebOb-doc-1.8.9-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-apache-libcloud-3.8.0-160000.3.1 * python313-WebOb-1.8.9-160000.3.1 * python313-soupsieve-2.6-160000.3.1 * python313-PyGithub-2.6.1-160000.3.1 * python313-Markdown-3.8.2-160000.3.1 * python313-handy-archives-0.2.0-160000.3.1 * python-WebOb-doc-1.8.9-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44889.html * https://bugzilla.suse.com/show_bug.cgi?id=1256310 * https://bugzilla.suse.com/show_bug.cgi?id=1256316 * https://bugzilla.suse.com/show_bug.cgi?id=1258223 * https://bugzilla.suse.com/show_bug.cgi?id=1261918 * https://bugzilla.suse.com/show_bug.cgi?id=1263802 * https://bugzilla.suse.com/show_bug.cgi?id=1268243 * https://bugzilla.suse.com/show_bug.cgi?id=1268324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:35:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:35:09 -0000 Subject: SUSE-SU-2026:22369-1: important: Security update for libaom Message-ID: <178292370954.5373.6834328995038743895@bea6e15a6baf> # Security update for libaom Announcement ID: SUSE-SU-2026:22369-1 Release Date: 2026-06-25T19:32:50Z Rating: important References: * bsc#1268650 * bsc#1268651 * bsc#1268653 * bsc#1268655 Cross-References: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211 CVSS scores: * CVE-2026-56208 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56209 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56210 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56211 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for libaom fixes the following issues * CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap- based buffer overflow and a process crash (bsc#1268650). * CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). * CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out- of-bounds heap read (bsc#1268653). * CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1082=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1082=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libaom3-debuginfo-3.11.0-160000.3.1 * aom-tools-3.11.0-160000.3.1 * aom-tools-debuginfo-3.11.0-160000.3.1 * libaom-debugsource-3.11.0-160000.3.1 * libaom3-3.11.0-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libaom3-debuginfo-3.11.0-160000.3.1 * aom-tools-3.11.0-160000.3.1 * aom-tools-debuginfo-3.11.0-160000.3.1 * libaom-debugsource-3.11.0-160000.3.1 * libaom3-3.11.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56208.html * https://www.suse.com/security/cve/CVE-2026-56209.html * https://www.suse.com/security/cve/CVE-2026-56210.html * https://www.suse.com/security/cve/CVE-2026-56211.html * https://bugzilla.suse.com/show_bug.cgi?id=1268650 * https://bugzilla.suse.com/show_bug.cgi?id=1268651 * https://bugzilla.suse.com/show_bug.cgi?id=1268653 * https://bugzilla.suse.com/show_bug.cgi?id=1268655 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:35:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:35:52 -0000 Subject: SUSE-SU-2026:22368-1: important: Security update for nodejs22 Message-ID: <178292375219.5373.7233555589042603415@bea6e15a6baf> # Security update for nodejs22 Announcement ID: SUSE-SU-2026:22368-1 Release Date: 2026-06-25T13:50:58Z Rating: important References: * bsc#1256576 * bsc#1259853 * bsc#1260455 * bsc#1260462 * bsc#1260463 * bsc#1260480 * bsc#1260482 * bsc#1260494 * bsc#1262274 * bsc#1266318 * bsc#1268097 * bsc#1268477 * bsc#1268479 * bsc#1268481 * bsc#1268482 * bsc#1268554 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268598 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 Cross-References: * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-21637 * CVE-2026-21710 * CVE-2026-21713 * CVE-2026-21714 * CVE-2026-21715 * CVE-2026-21716 * CVE-2026-21717 * CVE-2026-27135 * CVE-2026-40170 * CVE-2026-42338 * CVE-2026-48615 * CVE-2026-48617 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-6733 * CVE-2026-9496 * CVE-2026-9679 CVSS scores: * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21637 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21637 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21710 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21713 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-21713 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-21713 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21714 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21714 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21714 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21715 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-21715 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-21715 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-21716 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-21716 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-21716 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-21717 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-21717 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42338 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-42338 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-48615 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48615 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48617 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48617 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-48617 ( NVD ): 1.8 CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-9496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9496 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 26 vulnerabilities can now be installed. ## Description: This update for nodejs22 fixes the following issues Update to 22.23.0: * CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set- Cookie percent-decoding (bsc#1268477). * CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (bsc#1268481). * CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576). * CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455). * CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463). * CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480). * CVE-2026-21715: permission model bypass in realpathSync.native can allow file existence disclosure (bsc#1260482). * CVE-2026-21716: promise-based FileHandle methods can be used to modify file permissions and ownership (bsc#1260462). * CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-40170: ngtcp2: qlog parameters_set stack buffer overflow (bsc#1262274). * CVE-2026-42338: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097). * CVE-2026-48615: Proxy credentials leaked in ERR_PROXY_TUNNEL error message (bsc#1268598). * CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation (bsc#1268554). * CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker- controlled ORIGIN frames (bsc#1268618). * CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611). * CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1079=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1079=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * corepack22-22.23.0-160000.1.1 * nodejs22-debuginfo-22.23.0-160000.1.1 * nodejs22-debugsource-22.23.0-160000.1.1 * nodejs22-22.23.0-160000.1.1 * nodejs22-devel-22.23.0-160000.1.1 * npm22-22.23.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * nodejs22-docs-22.23.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * corepack22-22.23.0-160000.1.1 * nodejs22-debuginfo-22.23.0-160000.1.1 * nodejs22-debugsource-22.23.0-160000.1.1 * nodejs22-22.23.0-160000.1.1 * nodejs22-devel-22.23.0-160000.1.1 * npm22-22.23.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nodejs22-docs-22.23.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-21637.html * https://www.suse.com/security/cve/CVE-2026-21710.html * https://www.suse.com/security/cve/CVE-2026-21713.html * https://www.suse.com/security/cve/CVE-2026-21714.html * https://www.suse.com/security/cve/CVE-2026-21715.html * https://www.suse.com/security/cve/CVE-2026-21716.html * https://www.suse.com/security/cve/CVE-2026-21717.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-40170.html * https://www.suse.com/security/cve/CVE-2026-42338.html * https://www.suse.com/security/cve/CVE-2026-48615.html * https://www.suse.com/security/cve/CVE-2026-48617.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-9496.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1256576 * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1260455 * https://bugzilla.suse.com/show_bug.cgi?id=1260462 * https://bugzilla.suse.com/show_bug.cgi?id=1260463 * https://bugzilla.suse.com/show_bug.cgi?id=1260480 * https://bugzilla.suse.com/show_bug.cgi?id=1260482 * https://bugzilla.suse.com/show_bug.cgi?id=1260494 * https://bugzilla.suse.com/show_bug.cgi?id=1262274 * https://bugzilla.suse.com/show_bug.cgi?id=1266318 * https://bugzilla.suse.com/show_bug.cgi?id=1268097 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268554 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268598 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:36:01 -0000 Subject: SUSE-SU-2026:22367-1: important: Security update for docker Message-ID: <178292376188.5373.6911539706688654290@bea6e15a6baf> # Security update for docker Announcement ID: SUSE-SU-2026:22367-1 Release Date: 2026-06-25T12:44:41Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1081=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1081=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-160000.7.1 * docker-buildx-0.33.0-160000.7.1 * docker-debuginfo-29.4.0_ce-160000.7.1 * SUSE Linux Enterprise Server 16.0 (noarch) * docker-rootless-extras-29.4.0_ce-160000.7.1 * docker-fish-completion-29.4.0_ce-160000.7.1 * docker-zsh-completion-29.4.0_ce-160000.7.1 * docker-bash-completion-29.4.0_ce-160000.7.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * docker-rootless-extras-29.4.0_ce-160000.7.1 * docker-bash-completion-29.4.0_ce-160000.7.1 * docker-zsh-completion-29.4.0_ce-160000.7.1 * docker-fish-completion-29.4.0_ce-160000.7.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * docker-29.4.0_ce-160000.7.1 * docker-buildx-0.33.0-160000.7.1 * docker-debuginfo-29.4.0_ce-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:36:11 -0000 Subject: SUSE-SU-2026:22365-1: important: Security update for openCryptoki Message-ID: <178292377187.5373.14873821504148877204@bea6e15a6baf> # Security update for openCryptoki Announcement ID: SUSE-SU-2026:22365-1 Release Date: 2026-06-25T11:51:43Z Rating: important References: * bsc#1268745 * jsc#PED-14609 Cross-References: * CVE-2026-22791 * CVE-2026-23893 * CVE-2026-40253 CVSS scores: * CVE-2026-22791 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-22791 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-22791 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-22791 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23893 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-23893 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:L * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for openCryptoki fixes the following issues Upgrade openCryptoki to version 3.27 (jsc#PED-14609): * Add base support for PKCS#11 v3.2. * Add support for PKCS#11 v3.2 C_VerifySignature[Init|Update|Final]. * Add support for PKCS#11 v3.2 C_EncapsulateKey/C_DecapsulateKey. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with RSA- PKCS and RSA-OAEP mechanisms. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the ECDH mechanism. * Soft/EP11: Add support for PKCS#11 v3.2 en-/decapsulate with the DH-PKCS mechanism. * Soft: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires OpenSSL 3.5 or later, or the OQS-provider must be configured). * CCA: Add support for PKCS#11 v3.2 ML-DSA key type and mechanisms (requires CCA v8.4 or later) * EP11: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types and mechanisms (requires an EP11 host library v4.2 or later, and a CEX8P crypto card with firmware v9.6 or later on IBM z17, and v8.39 or later on IBM z16). * p11sak: Add support for PKCS#11 v3.2 ML-DSA and ML-KEM key types. * Soft/ICA: Add support for PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * p11sak: Add support for key wrapping with PKCS#11 v3.2 mechanisms CKM_ECDH_X_AES_KEY_WRAP and CKM_ECDH_COF_AES_KEY_WRAP. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.2 mechanism CKM_PUB_KEY_FROM_PRIV_KEY. * Soft/ICA/CCA/EP11: Add support for PKCS#11 v3.0 Edwards and Montgomery key types and mechanisms. * Soft/ICA: Support CKM_ECDH_AES_KEY_WRAP also for Montgomery keys. * p11sak: Add support for PKCS#11 v3.0 Edwards and Montgomery key types. * Soft: Add support for CKM_ECDH1_COFACTOR_DERIVE. * CCA: Add support for additional RSA public exponent values 5, 17, or 257. * p11sak: Add option to list-key command to show EP11 session IDs. * Make the maximum number of token objects supported configurable. * Fixes for CVE-2026-40253, CVE-2026-23893, and CVE-2026-22791. * Bug fixes. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1080=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1080=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openCryptoki-devel-3.27.0-160000.1.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 * openCryptoki-64bit-3.27.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openCryptoki-devel-3.27.0-160000.1.1 * openCryptoki-64bit-debuginfo-3.27.0-160000.1.1 * openCryptoki-debuginfo-3.27.0-160000.1.1 * openCryptoki-3.27.0-160000.1.1 * openCryptoki-debugsource-3.27.0-160000.1.1 * openCryptoki-64bit-3.27.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22791.html * https://www.suse.com/security/cve/CVE-2026-23893.html * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1268745 * https://jira.suse.com/browse/PED-14609 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:36:19 -0000 Subject: SUSE-SU-2026:22364-1: important: Security update for libssh2_org Message-ID: <178292377987.5373.15851288437905325440@bea6e15a6baf> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:22364-1 Release Date: 2026-06-25T11:51:43Z Rating: important References: * bsc#1268530 * bsc#1268531 Cross-References: * CVE-2026-55199 * CVE-2026-55200 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55200 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55200 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55200 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55200 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libssh2_org fixes the following issues * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). * CVE-2026-55200: out-of-Bounds write via Unchecked packet_length in transport.c (bsc#1268531). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1078=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1078=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libssh2-1-debuginfo-1.11.1-160000.4.1 * libssh2-devel-1.11.1-160000.4.1 * libssh2_org-debugsource-1.11.1-160000.4.1 * libssh2-1-1.11.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libssh2-devel-1.11.1-160000.4.1 * libssh2_org-debugsource-1.11.1-160000.4.1 * libssh2-1-debuginfo-1.11.1-160000.4.1 * libssh2-1-1.11.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://www.suse.com/security/cve/CVE-2026-55200.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 * https://bugzilla.suse.com/show_bug.cgi?id=1268531 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:36:25 -0000 Subject: SUSE-SU-2026:22363-1: important: Security update for libnfs Message-ID: <178292378542.5373.14283302091628780336@bea6e15a6baf> # Security update for libnfs Announcement ID: SUSE-SU-2026:22363-1 Release Date: 2026-06-25T11:50:17Z Rating: important References: * bsc#1268135 Cross-References: * CVE-2026-53689 CVSS scores: * CVE-2026-53689 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-53689 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libnfs fixes the following issue * CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1076=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1076=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-5.0.3-160000.4.1 * libnfs14-5.0.3-160000.4.1 * utils-libnfs-debuginfo-5.0.3-160000.4.1 * libnfs-debugsource-5.0.3-160000.4.1 * libnfs14-debuginfo-5.0.3-160000.4.1 * utils-libnfs-5.0.3-160000.4.1 * libnfs-devel-5.0.3-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libnfs-debuginfo-5.0.3-160000.4.1 * libnfs14-5.0.3-160000.4.1 * utils-libnfs-debuginfo-5.0.3-160000.4.1 * libnfs-debugsource-5.0.3-160000.4.1 * libnfs14-debuginfo-5.0.3-160000.4.1 * utils-libnfs-5.0.3-160000.4.1 * libnfs-devel-5.0.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53689.html * https://bugzilla.suse.com/show_bug.cgi?id=1268135 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:36:44 -0000 Subject: SUSE-SU-2026:22360-1: important: Security update for python-starlette Message-ID: <178292380468.5373.2835291741816625458@bea6e15a6baf> # Security update for python-starlette Announcement ID: SUSE-SU-2026:22360-1 Release Date: 2026-06-24T21:38:49Z Rating: important References: * bsc#1268389 * bsc#1268517 * bsc#1268520 Cross-References: * CVE-2026-48817 * CVE-2026-54282 * CVE-2026-54283 CVSS scores: * CVE-2026-48817 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48817 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54282 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-54282 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54282 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54282 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54283 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54283 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-starlette fixes the following issues * CVE-2026-48817: arbitrary HTTP method dispatched to `HTTPEndpoint` attributes via `getattr` (bsc#1268389). * CVE-2026-54282: request path that lacks a leading forward slash can lead to request.url.hostname manipulation (bsc#1268520). * CVE-2026-54283: urlencoded request body with an oversized data can lead to a denial of service (bsc#1268517). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1066=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1066=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-starlette-0.41.3-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-starlette-0.41.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48817.html * https://www.suse.com/security/cve/CVE-2026-54282.html * https://www.suse.com/security/cve/CVE-2026-54283.html * https://bugzilla.suse.com/show_bug.cgi?id=1268389 * https://bugzilla.suse.com/show_bug.cgi?id=1268517 * https://bugzilla.suse.com/show_bug.cgi?id=1268520 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:36:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:36:56 -0000 Subject: SUSE-SU-2026:22358-1: important: Security update for dracut Message-ID: <178292381657.5373.7411903793222205105@bea6e15a6baf> # Security update for dracut Announcement ID: SUSE-SU-2026:22358-1 Release Date: 2026-06-24T21:37:46Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.722.gdd9d67ff5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1067=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1067=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dracut-tools-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-ima-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-extra-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-fips-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debugsource-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debuginfo-059+suse.722.gdd9d67ff5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dracut-tools-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-ima-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-extra-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-fips-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debugsource-059+suse.722.gdd9d67ff5-160000.1.1 * dracut-debuginfo-059+suse.722.gdd9d67ff5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:37:11 -0000 Subject: SUSE-SU-2026:22356-1: moderate: Security update for python-idna Message-ID: <178292383199.5373.17636758447386964813@bea6e15a6baf> # Security update for python-idna Announcement ID: SUSE-SU-2026:22356-1 Release Date: 2026-06-24T21:37:46Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1061=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1061=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-idna-3.10-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-idna-3.10-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:37:17 -0000 Subject: SUSE-SU-2026:22355-1: low: Security update for libgcrypt Message-ID: <178292383759.5373.13637129964139916452@bea6e15a6baf> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:22355-1 Release Date: 2026-06-24T21:36:29Z Rating: low References: * bsc#1262693 Cross-References: * CVE-2026-41990 CVSS scores: * CVE-2026-41990 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41990 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-41990 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue * CVE-2026-41990: lack of bound check can lead to mishandling of Dilithium signing (bsc#1262693). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1060=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1060=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgcrypt-devel-1.12.1-160000.2.1 * libgcrypt20-1.12.1-160000.2.1 * libgcrypt20-debuginfo-1.12.1-160000.2.1 * libgcrypt-debugsource-1.12.1-160000.2.1 * libgcrypt-devel-debuginfo-1.12.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libgcrypt20-x86-64-v3-debuginfo-1.12.1-160000.2.1 * libgcrypt20-x86-64-v3-1.12.1-160000.2.1 * libgcrypt-devel-x86-64-v3-1.12.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgcrypt-devel-1.12.1-160000.2.1 * libgcrypt20-1.12.1-160000.2.1 * libgcrypt20-debuginfo-1.12.1-160000.2.1 * libgcrypt-debugsource-1.12.1-160000.2.1 * libgcrypt-devel-debuginfo-1.12.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libgcrypt20-x86-64-v3-debuginfo-1.12.1-160000.2.1 * libgcrypt20-x86-64-v3-1.12.1-160000.2.1 * libgcrypt-devel-x86-64-v3-1.12.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41990.html * https://bugzilla.suse.com/show_bug.cgi?id=1262693 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:37:28 -0000 Subject: SUSE-SU-2026:22353-1: moderate: Security update for perl-libwww-perl Message-ID: <178292384829.5373.4470521024558138810@bea6e15a6baf> # Security update for perl-libwww-perl Announcement ID: SUSE-SU-2026:22353-1 Release Date: 2026-06-24T19:41:53Z Rating: moderate References: * bsc#1265156 Cross-References: * CVE-2026-8368 CVSS scores: * CVE-2026-8368 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-8368 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-libwww-perl fixes the following issue * CVE-2026-8368: authorization and proxy-authorization headers are leaked on cross-origin redirects (bsc#1265156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1058=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1058=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-libwww-perl-6.770.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-libwww-perl-6.770.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8368.html * https://bugzilla.suse.com/show_bug.cgi?id=1265156 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:37:36 -0000 Subject: SUSE-SU-2026:22352-1: moderate: Security update for openssh Message-ID: <178292385694.5373.5890367491192792680@bea6e15a6baf> # Security update for openssh Announcement ID: SUSE-SU-2026:22352-1 Release Date: 2026-06-24T15:22:37Z Rating: moderate References: * bsc#1259642 * bsc#1261441 * bsc#1264568 Cross-References: * CVE-2026-3497 * CVE-2026-35388 CVSS scores: * CVE-2026-3497 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-3497 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-3497 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3497 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-3497 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35388 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-35388 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-35388 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-35388 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for openssh fixes the following issues Security fixes: * CVE-2026-3497: information disclosure or denial of service due to uninitialized variables (bsc#1259642). * CVE-2026-35388: omitted connection multiplexing confirmation for proxy-mode multiplexing sessions (bsc#1261441). * openssh potential security issue when validating mac or ciphers (bsc#1264568). Other fixes: * Improve %prep LDAP regex to preserve subdirectories (e.g., openbsd-compat/) and handle optional [ab]/ prefixes. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1057=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1057=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openssh-10.0p2-160000.6.1 * openssh-common-10.0p2-160000.6.1 * openssh-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-debuginfo-10.0p2-160000.6.1 * openssh-cavs-debuginfo-10.0p2-160000.6.1 * openssh-server-10.0p2-160000.6.1 * openssh-clients-10.0p2-160000.6.1 * openssh-debugsource-10.0p2-160000.6.1 * openssh-cavs-10.0p2-160000.6.1 * openssh-askpass-gnome-debugsource-10.0p2-160000.6.1 * openssh-server-debuginfo-10.0p2-160000.6.1 * openssh-clients-debuginfo-10.0p2-160000.6.1 * openssh-server-config-rootlogin-10.0p2-160000.6.1 * openssh-common-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-10.0p2-160000.6.1 * openssh-helpers-10.0p2-160000.6.1 * openssh-helpers-debuginfo-10.0p2-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openssh-10.0p2-160000.6.1 * openssh-common-10.0p2-160000.6.1 * openssh-cavs-debuginfo-10.0p2-160000.6.1 * openssh-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-debuginfo-10.0p2-160000.6.1 * openssh-server-10.0p2-160000.6.1 * openssh-clients-10.0p2-160000.6.1 * openssh-debugsource-10.0p2-160000.6.1 * openssh-cavs-10.0p2-160000.6.1 * openssh-askpass-gnome-debugsource-10.0p2-160000.6.1 * openssh-server-debuginfo-10.0p2-160000.6.1 * openssh-clients-debuginfo-10.0p2-160000.6.1 * openssh-server-config-rootlogin-10.0p2-160000.6.1 * openssh-common-debuginfo-10.0p2-160000.6.1 * openssh-askpass-gnome-10.0p2-160000.6.1 * openssh-helpers-10.0p2-160000.6.1 * openssh-helpers-debuginfo-10.0p2-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3497.html * https://www.suse.com/security/cve/CVE-2026-35388.html * https://bugzilla.suse.com/show_bug.cgi?id=1259642 * https://bugzilla.suse.com/show_bug.cgi?id=1261441 * https://bugzilla.suse.com/show_bug.cgi?id=1264568 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:37:42 -0000 Subject: SUSE-SU-2026:22351-1: important: Security update for MozillaFirefox Message-ID: <178292386282.5373.18026748793272792774@bea6e15a6baf> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:22351-1 Release Date: 2026-06-24T08:25:21Z Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issue Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1056=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1056=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-160000.1.1 * MozillaFirefox-debuginfo-140.12.0-160000.1.1 * MozillaFirefox-140.12.0-160000.1.1 * MozillaFirefox-translations-common-140.12.0-160000.1.1 * MozillaFirefox-debugsource-140.12.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * MozillaFirefox-devel-140.12.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-160000.1.1 * MozillaFirefox-debuginfo-140.12.0-160000.1.1 * MozillaFirefox-140.12.0-160000.1.1 * MozillaFirefox-translations-common-140.12.0-160000.1.1 * MozillaFirefox-debugsource-140.12.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * MozillaFirefox-devel-140.12.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:37:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:37:56 -0000 Subject: SUSE-SU-2026:22349-1: important: Security update for sg3_utils Message-ID: <178292387685.5373.6135846270807583845@bea6e15a6baf> # Security update for sg3_utils Announcement ID: SUSE-SU-2026:22349-1 Release Date: 2026-06-23T13:50:20Z Rating: important References: * bsc#1267823 * bsc#1268201 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for sg3_utils fixes the following issues: * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823) * rescan-scsi-bus.sh: quote $id_serial in findmultipath call (bsc#1268201) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1053=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1053=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsgutils-devel-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debugsource-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils2-1_48-2-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils2-1_48-2-1.48~20221101+7.f75279c0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsgutils2-1_48-2-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debugsource-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-debuginfo-1.48~20221101+7.f75279c0-160000.1.1 * sg3_utils-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils-devel-1.48~20221101+7.f75279c0-160000.1.1 * libsgutils2-1_48-2-1.48~20221101+7.f75279c0-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267823 * https://bugzilla.suse.com/show_bug.cgi?id=1268201 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:38:18 -0000 Subject: SUSE-SU-2026:22347-1: important: Security update for 7zip Message-ID: <178292389826.5373.5779614902537960040@bea6e15a6baf> # Security update for 7zip Announcement ID: SUSE-SU-2026:22347-1 Release Date: 2026-06-23T12:46:58Z Rating: important References: * bsc#1267421 * bsc#1267858 * bsc#1267859 * bsc#1267860 * bsc#1267861 * bsc#1267862 * bsc#1267863 * bsc#1267864 Cross-References: * CVE-2026-48092 * CVE-2026-48095 * CVE-2026-48101 * CVE-2026-48102 * CVE-2026-48103 * CVE-2026-48104 * CVE-2026-48111 * CVE-2026-48112 CVSS scores: * CVE-2026-48092 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48092 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48092 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48092 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-48095 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48095 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-48101 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48101 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-48102 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48102 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48102 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48103 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48103 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48103 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48104 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48104 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48104 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-48111 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48111 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48111 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-48112 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-48112 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-48112 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for 7zip fixes the following issues Update to 26.01: * CVE-2026-48092: Information disclosure in 32-bit builds due to heap memory disclosure (bsc#1267858). * CVE-2026-48095: Heap buffer overflow via NTFS compressed stream buffer under-allocation (bsc#1267421). * CVE-2026-48101: Information Disclosure via uninitialized memory in UEFI capsule parser (bsc#1267859). * CVE-2026-48102: Information disclosure and denial of service via crafted UDF image (bsc#1267860). * CVE-2026-48103: off-by-one heap out-of-bounds read (bsc#1267861). * CVE-2026-48104: Uninitialized heap read in SquashFS archive handler (bsc#1267862). * CVE-2026-48111: off-by-one out-of-bounds read in ParseDepedencyExpression function (bsc#1267863). * CVE-2026-48112: heap out-of-bounds read in BSD SYMDEF parser (bsc#1267864). Changes: * linux version of 7-Zip can use huge pages (2 MB pages). It can increase compression speed for 10% for 7z/xz/LZMA/LZMA2 compression. * new -spo[d|c|r] switch specifies the path generation mode for the output directory for archive extraction. The output directory path is generated from the path specified in the -o{dir_path} switch and the name of the archive being unpacked. -spod : for Linux/Posix/macOS: -o{dir_path} specifies the direct path to the output directory. The asterisk (_) character in {dir_path} will not be replaced by the archive name. -spoc : 7-Zip will concatenate the path specified in -o{dir_path} with the archive name to form the final path to the output directory. -spor : 7-Zip will replace asterisk (_) character in the path specified in the -o{dir_path} with the archive name. This is the default option. * some bugs were fixed. * Update to 26.00: * improved code for ZIP, CPIO, RAR, UFD, QCOW, Compound. * 7-Zip File Manager: improved sorting order of the file list. It uses file name as secondary sorting key.: * 7-Zip File Manager: improved Benchmark to support systems with more than 64 CPU threads. * bug fixed: 7-Zip could not correctly extract TAR archives containing sparse files ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1051=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1051=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * 7zip-26.01-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * 7zip-26.01-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48092.html * https://www.suse.com/security/cve/CVE-2026-48095.html * https://www.suse.com/security/cve/CVE-2026-48101.html * https://www.suse.com/security/cve/CVE-2026-48102.html * https://www.suse.com/security/cve/CVE-2026-48103.html * https://www.suse.com/security/cve/CVE-2026-48104.html * https://www.suse.com/security/cve/CVE-2026-48111.html * https://www.suse.com/security/cve/CVE-2026-48112.html * https://bugzilla.suse.com/show_bug.cgi?id=1267421 * https://bugzilla.suse.com/show_bug.cgi?id=1267858 * https://bugzilla.suse.com/show_bug.cgi?id=1267859 * https://bugzilla.suse.com/show_bug.cgi?id=1267860 * https://bugzilla.suse.com/show_bug.cgi?id=1267861 * https://bugzilla.suse.com/show_bug.cgi?id=1267862 * https://bugzilla.suse.com/show_bug.cgi?id=1267863 * https://bugzilla.suse.com/show_bug.cgi?id=1267864 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:38:36 -0000 Subject: SUSE-SU-2026:22344-1: moderate: Security update for cosign Message-ID: <178292391652.5373.11524259091651096095@bea6e15a6baf> # Security update for cosign Announcement ID: SUSE-SU-2026:22344-1 Release Date: 2026-06-22T15:12:24Z Rating: moderate References: * bsc#1261859 * jsc#SLE-23879 Cross-References: * CVE-2026-39395 CVSS scores: * CVE-2026-39395 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39395 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39395 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-39395 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for cosign fixes the following issues Security issue: * CVE-2026-39395: Incorrect attestation verification due to malformed payloads or mismatched predicate types (bsc#1261859). Non security issue: * Update to version 3.0.5 (jsc#SLE-23879). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1049=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1049=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cosign-3.0.6-160000.1.1 * cosign-debuginfo-3.0.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cosign-3.0.6-160000.1.1 * cosign-debuginfo-3.0.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39395.html * https://bugzilla.suse.com/show_bug.cgi?id=1261859 * https://jira.suse.com/browse/SLE-23879 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:38:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:38:42 -0000 Subject: SUSE-SU-2026:22343-1: moderate: Security update for firewalld Message-ID: <178292392217.5373.174262941130556782@bea6e15a6baf> # Security update for firewalld Announcement ID: SUSE-SU-2026:22343-1 Release Date: 2026-06-22T15:10:04Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1045=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1045=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 * firewalld-zsh-completion-2.1.2-160000.3.1 * firewalld-bash-completion-2.1.2-160000.3.1 * firewalld-lang-2.1.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python3-firewall-2.1.2-160000.3.1 * firewalld-2.1.2-160000.3.1 * firewalld-zsh-completion-2.1.2-160000.3.1 * firewalld-bash-completion-2.1.2-160000.3.1 * firewalld-lang-2.1.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:39:07 -0000 Subject: SUSE-SU-2026:22340-1: moderate: Security update for mutt Message-ID: <178292394784.5373.5284863201970868319@bea6e15a6baf> # Security update for mutt Announcement ID: SUSE-SU-2026:22340-1 Release Date: 2026-06-22T14:45:20Z Rating: moderate References: * bsc#1263892 * bsc#1263893 * bsc#1263894 * bsc#1263895 * bsc#1263896 * bsc#1263897 * bsc#1264047 Cross-References: * CVE-2026-43859 * CVE-2026-43860 * CVE-2026-43861 * CVE-2026-43862 * CVE-2026-43863 * CVE-2026-43864 CVSS scores: * CVE-2026-43859 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43859 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43859 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43860 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43860 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43860 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43861 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43861 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43861 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43862 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43862 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43862 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-43863 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43863 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43863 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43864 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43864 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43864 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for mutt fixes the following issues * CVE-2026-43859: `strfcpy` used instead of `memcpy` for the IMAP `auth_cram` MD5 digest (bsc#1263897). * CVE-2026-43860: truncation of `hash_passwd` by one byte for IMAP `auth_cram` MD5 digest (bsc#1263896). * CVE-2026-43861: missing check for `\0` in `url_pct_decode` (bsc#1263895). * CVE-2026-43862: mishandling of the `imap_auth_gss` security level (bsc#1263894). * CVE-2026-43863: infinite loop in `data_object_to_stream` in `crypt-gpgme.c` (bsc#1263893). * CVE-2026-43864: NULL pointer dereference in function `show_sig_summary` (bsc#1263892). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1028=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1028=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * mutt-doc-2.2.16-160000.2.1 * mutt-lang-2.2.16-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * mutt-debuginfo-2.2.16-160000.2.1 * mutt-debugsource-2.2.16-160000.2.1 * mutt-2.2.16-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * mutt-debuginfo-2.2.16-160000.2.1 * mutt-debugsource-2.2.16-160000.2.1 * mutt-2.2.16-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * mutt-doc-2.2.16-160000.2.1 * mutt-lang-2.2.16-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43859.html * https://www.suse.com/security/cve/CVE-2026-43860.html * https://www.suse.com/security/cve/CVE-2026-43861.html * https://www.suse.com/security/cve/CVE-2026-43862.html * https://www.suse.com/security/cve/CVE-2026-43863.html * https://www.suse.com/security/cve/CVE-2026-43864.html * https://bugzilla.suse.com/show_bug.cgi?id=1263892 * https://bugzilla.suse.com/show_bug.cgi?id=1263893 * https://bugzilla.suse.com/show_bug.cgi?id=1263894 * https://bugzilla.suse.com/show_bug.cgi?id=1263895 * https://bugzilla.suse.com/show_bug.cgi?id=1263896 * https://bugzilla.suse.com/show_bug.cgi?id=1263897 * https://bugzilla.suse.com/show_bug.cgi?id=1264047 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:39:19 -0000 Subject: SUSE-SU-2026:22338-1: moderate: Security update for avahi Message-ID: <178292395975.5373.7781989760691212560@bea6e15a6baf> # Security update for avahi Announcement ID: SUSE-SU-2026:22338-1 Release Date: 2026-06-22T14:40:15Z Rating: moderate References: * bsc#1257235 * bsc#1261546 Cross-References: * CVE-2026-24401 * CVE-2026-34933 CVSS scores: * CVE-2026-24401 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-24401 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-24401 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-34933 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34933 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for avahi fixes the following issues: * CVE-2026-34933: reachable assertion in `transport_flags_from_domain` can crash the `avahi-daemon` (bsc#1261546). * CVE-2026-24401: unsolicited mDNS responses containing a recursive CNAME record can crash the `avahi-daemon` (bsc#1257235). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1026=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1026=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * avahi-autoipd-0.8-160000.5.1 * libhowl0-debuginfo-0.8-160000.5.1 * libavahi-common3-0.8-160000.5.1 * libavahi-glib-devel-0.8-160000.5.1 * libavahi-client3-debuginfo-0.8-160000.5.1 * libdns_sd-0.8-160000.5.1 * libavahi-glib1-0.8-160000.5.1 * libavahi-core7-0.8-160000.5.1 * libdns_sd-debuginfo-0.8-160000.5.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.5.1 * avahi-utils-gtk-0.8-160000.5.1 * libavahi-ui-gtk3-0-0.8-160000.5.1 * avahi-autoipd-debuginfo-0.8-160000.5.1 * typelib-1_0-Avahi-0_6-0.8-160000.5.1 * avahi-debuginfo-0.8-160000.5.1 * libavahi-core7-debuginfo-0.8-160000.5.1 * libavahi-gobject-devel-0.8-160000.5.1 * libavahi-devel-0.8-160000.5.1 * avahi-0.8-160000.5.1 * libavahi-client3-0.8-160000.5.1 * libavahi-common3-debuginfo-0.8-160000.5.1 * libavahi-libevent1-debuginfo-0.8-160000.5.1 * python313-avahi-0.8-160000.5.1 * avahi-utils-debuginfo-0.8-160000.5.1 * libavahi-gobject0-debuginfo-0.8-160000.5.1 * libhowl0-0.8-160000.5.1 * avahi-utils-gtk-debuginfo-0.8-160000.5.1 * avahi-debugsource-0.8-160000.5.1 * avahi-compat-mDNSResponder-devel-0.8-160000.5.1 * libavahi-gobject0-0.8-160000.5.1 * avahi-glib2-debugsource-0.8-160000.5.1 * python3-avahi-gtk-0.8-160000.5.1 * libavahi-glib1-debuginfo-0.8-160000.5.1 * libavahi-libevent1-0.8-160000.5.1 * avahi-utils-0.8-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * avahi-lang-0.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * avahi-autoipd-0.8-160000.5.1 * libhowl0-debuginfo-0.8-160000.5.1 * libavahi-common3-0.8-160000.5.1 * libavahi-glib-devel-0.8-160000.5.1 * libavahi-client3-debuginfo-0.8-160000.5.1 * libdns_sd-0.8-160000.5.1 * libavahi-glib1-0.8-160000.5.1 * libavahi-core7-0.8-160000.5.1 * libdns_sd-debuginfo-0.8-160000.5.1 * libavahi-ui-gtk3-0-debuginfo-0.8-160000.5.1 * avahi-utils-gtk-0.8-160000.5.1 * libavahi-ui-gtk3-0-0.8-160000.5.1 * typelib-1_0-Avahi-0_6-0.8-160000.5.1 * avahi-autoipd-debuginfo-0.8-160000.5.1 * avahi-debuginfo-0.8-160000.5.1 * libavahi-core7-debuginfo-0.8-160000.5.1 * libavahi-devel-0.8-160000.5.1 * avahi-0.8-160000.5.1 * libavahi-gobject-devel-0.8-160000.5.1 * libavahi-client3-0.8-160000.5.1 * python313-avahi-0.8-160000.5.1 * libavahi-common3-debuginfo-0.8-160000.5.1 * libavahi-libevent1-debuginfo-0.8-160000.5.1 * avahi-utils-debuginfo-0.8-160000.5.1 * libavahi-gobject0-debuginfo-0.8-160000.5.1 * libhowl0-0.8-160000.5.1 * avahi-utils-gtk-debuginfo-0.8-160000.5.1 * avahi-debugsource-0.8-160000.5.1 * avahi-compat-mDNSResponder-devel-0.8-160000.5.1 * libavahi-gobject0-0.8-160000.5.1 * avahi-glib2-debugsource-0.8-160000.5.1 * python3-avahi-gtk-0.8-160000.5.1 * libavahi-glib1-debuginfo-0.8-160000.5.1 * libavahi-libevent1-0.8-160000.5.1 * avahi-utils-0.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * avahi-lang-0.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-24401.html * https://www.suse.com/security/cve/CVE-2026-34933.html * https://bugzilla.suse.com/show_bug.cgi?id=1257235 * https://bugzilla.suse.com/show_bug.cgi?id=1261546 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:39:34 -0000 Subject: SUSE-SU-2026:22335-1: moderate: Security update for postfix Message-ID: <178292397405.5373.376527601385960481@bea6e15a6baf> # Security update for postfix Announcement ID: SUSE-SU-2026:22335-1 Release Date: 2026-06-22T14:37:16Z Rating: moderate References: * bsc#1264062 Cross-References: * CVE-2026-43964 CVSS scores: * CVE-2026-43964 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43964 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for postfix fixes the following issue * CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1032=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1032=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postfix-mysql-debuginfo-3.10.2-160000.3.1 * postfix-postgresql-debuginfo-3.10.2-160000.3.1 * postfix-3.10.2-160000.3.1 * postfix-mysql-3.10.2-160000.3.1 * postfix-debugsource-3.10.2-160000.3.1 * postfix-debuginfo-3.10.2-160000.3.1 * postfix-postgresql-3.10.2-160000.3.1 * postfix-ldap-3.10.2-160000.3.1 * postfix-ldap-debuginfo-3.10.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postfix-doc-3.10.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postfix-mysql-debuginfo-3.10.2-160000.3.1 * postfix-postgresql-debuginfo-3.10.2-160000.3.1 * postfix-3.10.2-160000.3.1 * postfix-debugsource-3.10.2-160000.3.1 * postfix-mysql-3.10.2-160000.3.1 * postfix-postgresql-3.10.2-160000.3.1 * postfix-debuginfo-3.10.2-160000.3.1 * postfix-ldap-3.10.2-160000.3.1 * postfix-ldap-debuginfo-3.10.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postfix-doc-3.10.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43964.html * https://bugzilla.suse.com/show_bug.cgi?id=1264062 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:39:43 -0000 Subject: SUSE-SU-2026:22333-1: important: Security update for 389-ds Message-ID: <178292398357.5373.266826211911738872@bea6e15a6baf> # Security update for 389-ds Announcement ID: SUSE-SU-2026:22333-1 Release Date: 2026-06-22T14:37:16Z Rating: important References: * bsc#1265898 Cross-References: * CVE-2026-9064 CVSS scores: * CVE-2026-9064 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9064 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for 389-ds fixes the following issue * CVE-2026-9064: unbounded LDAP controls count in `get_ldapmessage_controls_ext()` can lead to amplified CPU time and heap allocation and a denial of service (bsc#1265898). Changes for 389-ds: * Update to version 3.0.6~git337.647f49042: * Issue 7541 - heap-buffer-overflows in __aclp__normalize_acltxt() (#7542) * Issue 7531 - Fix LMDB replication regression_m2 failures and core dumps (#7575) * Issue 7496 - fix cherry-pick error * Issue 7490 - Enable USDT probes by default in RPM (#7491) * Issue 7576 - Fix leak of temporary attribute syntax hash tables after schema reload * Issue 7558 - During online import, the IDL should be created with in-depth first approach (#7559) * Issue 7500 - Prevent unsigned integer underflow during stalled import * Issue 7562 - Error: NssSsl.add_cert() got an unexpected keyword argument 'input_file' (#7563) * Issue 7560 - lib389 - Add helper function for checking ASAN files * Issue 7539 - Server shutdown during online reindex may lead to data loss (#7540) * Issue 7549 - Substring index should validate minimum nsSubStrBegin/nsSubStrEnd values (#7550) * Issue 7440 - Substring index produces empty results and can crash when non- default nsSubStrBegin/nsSubStrEnd lengths are configured (#7441) * Fix test389 imports on older branches * Issue 7267 - MDB_BAD_VALSIZE error when updating index (#7268) * Issue 7327 - dsctl healthcheck DSMOLE0001 inaccurate recommendations with multiple backends (#7328) * Issue 7372 - Reindex adds tombstones to ancestorid causing export failures (#7373) * Issue 7437 - LeakSanitizer: memory leaks in CoS cache error paths (#7438) * Issue 6922 - AddressSanitizer: leaks found by acl test suite * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7556) * Issue 7554 - deref plugin null pointer dereference if ber_init fails * Issue 7493 - RFE - Add ShadowAccount fixup task * Issue 7507 - UI - cleanup style and alignments * Issue 7514 - Crash when doing moddn on very large subtree * Issue 7516 - dblayer_bulk_nextdata should not return an error when maxrecords is hit * Issue 7496 - Fix latest GCC compiler warnings * Issue 7503 - CVE-2026-9064 - Add a limit to the number controls per operation * Issue 7300 - RFE - Add OS-level thread names to all server threads (#7301) * Issue 7307 - RFE - Expose work queue and worker utilization metrics (#7308) * Issue 7464 - CLI - allow dsidm to work with other user types * Issue 7457 - Refactor memberOf perf test (#7458) * Issue 7452 - UI - password polices - reorganize settings * Issue 7431 - password policy - passwordBadWords is ignored in local policies * Issue 7155 - build_candidate_list - Database error 11 with range search (#7156) * Issue 7426 - logconv.py is out of sync with server-emitted note codes (#7427) * Issue 7417 - UI - global password policy syntax settings missing passwordMaxRepeats * Issue 3555 - UI - Fix audit issue with npm - brace-expansion (#7411) * Issue 7088 - Change log level for "Can't locate CSN" error message * Issue 7423 - cleanup pblock after freeing pre/post entries * Issue 7418 - Use-after-free in deferred memberof (#7419) * Issue 7407 - dbscan -k option - fix cherry-pick error * Issue 7407 - dbscan -k option display entries that do not match the specified key * Issue 7404 - fix latest compiler warnings(cherry-pick issue) * Issue 7404 - fix latest compiler warnings * Issue 7394 - UI - Manual typing of ports can leave out digits (#7395) * Issue 7277 - UI - Fix Japanese translation errors errors in Cockpit UI (#7386) * Issue 7246 - correct formatting of 'Gen as CSN' in dsctl get-nsstate output (#7247) * Issue 7126 - WARN - keys2idl - received NULL idl from index_read_ext_allids (#7127) * Issue 7370 - Runtime LSan/TSan injection for pytest (#7371) * Issue 7378 - Make sure suffix entry always gets assigned ID 1 * Issue 7380 - Internal op with negative wtime and large optime (#7381) * Issue 7362 - UI - Some FormSelect onChange parameters are reversed * Issue 7368 - UI - global password policy page is missing passwordmintokenlength * Issue 7366 - Memory leaks in syncrepl plugin during persistent search operations (#7367) * Issue 3658 - UI/CLI - show progress of db tasks * Issue 7284 - CI - Fix test_grace_limit_section after pwpolicy validation fix (#7357) * Issue 7271 - Add test for retrocl trimming shutdown crash (#7356) * Issue 3555 - UI - Fix audit issue with npm - flatted, picomatch (#7364) * Issue 7337 - UI - refactor all error handling to use getApiErrorMessge * Issue 1704 - DNA plugin creates invalid shared config entry with port 0 (#7352) * Issue 6753 - Removing ticket 477828 test and porting to DSLdapObject (#6989) * Issue 7348 - CI - Fix failing dsconf security CLI add cert test (#7349) * Issue 7346 - DS does not handle escape char in bind user (#7347) * Issue 7322 - Fix cherry-pick error (reject repl agmt that points to itself) * Issue 7322 - Reject adding a replication agreement that points to itself * Issue 7312 - UI - Database Maximum Size cannot be easily set by typing (#7313) * Issue 7342 - CI - repl config regression (#7343) * Issue 7339 - Return the exact DN during export * Issue - UI - Improve suffix import LDIF table * Issue 7325 - UI - new error parser missing import * Issue 7325 - UI - create an error parser for cockpit spawn errors * Issue 7319 - Action menu for certificates remains in empty certificate list (#7320) * Issue 7265 - CI - fix retro changelog maxage validation test * Issue 7093 - A password policy can be created even when an identical policy already exists (#7283) * Issue 7316 - UI - update npm module immutable * Issue 7233 - test_produce_division_by_zero fails with IsADirectoryError in conftest.py (#7234) * Issue 7314 - UI - Add progress steppers to Security, Database, and Replication tabs * Issuei 7281 - UI - Add encryption module management * Issue 7271 - Add new plugin pre-close function check to plugin_invoke_plugin_pb * Issue 7304 - retrocl should not cache DN * Issue 7265 - Add dse modify callback to validate retrocl trimming settings * Issue 7152 - ns-slapd fails to shutdown when deferred memberof update is in progress (#7187) * Issue 3555 - UI - Fix audit issue with npm - ajv, minimatch (#7298) * Issue 7291 - Crash when configuring a replica with an incorrect nsds5ReplicaRoot (#7292) * Issue 7271 - implement a pre-close plugin function * Issue 7295 - changelog max age validation cherry-pick error * Issue 7281 - RFE - CLI - add support to managing additional encryption modules * Issue 7265 - changelog maxage validation is not strict enough * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7285) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1023=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1023=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsvrcore0-debuginfo-3.0.6~git337.647f49042-160000.1.1 * libsvrcore0-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debugsource-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-devel-3.0.6~git337.647f49042-160000.1.1 * lib389-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-3.0.6~git337.647f49042-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsvrcore0-debuginfo-3.0.6~git337.647f49042-160000.1.1 * libsvrcore0-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debugsource-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-3.0.6~git337.647f49042-160000.1.1 * 389-ds-debuginfo-3.0.6~git337.647f49042-160000.1.1 * 389-ds-devel-3.0.6~git337.647f49042-160000.1.1 * lib389-3.0.6~git337.647f49042-160000.1.1 * 389-ds-snmp-3.0.6~git337.647f49042-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9064.html * https://bugzilla.suse.com/show_bug.cgi?id=1265898 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:39:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:39:54 -0000 Subject: SUSE-SU-2026:22332-1: moderate: Security update for util-linux Message-ID: <178292399416.5373.9349942519823026244@bea6e15a6baf> # Security update for util-linux Announcement ID: SUSE-SU-2026:22332-1 Release Date: 2026-06-22T14:34:40Z Rating: moderate References: * bsc#1261606 Cross-References: * CVE-2026-27456 CVSS scores: * CVE-2026-27456 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27456 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for util-linux fixes the following issue * CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1040=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1040=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libsmartcols1-debuginfo-2.41.1-160000.4.1 * uuidd-debuginfo-2.41.1-160000.4.1 * libmount-devel-static-2.41.1-160000.4.1 * util-linux-2.41.1-160000.4.1 * libuuid-devel-2.41.1-160000.4.1 * libuuid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-static-2.41.1-160000.4.1 * libuuid-devel-static-2.41.1-160000.4.1 * python-libmount-debugsource-2.41.1-160000.4.1 * libblkid-devel-2.41.1-160000.4.1 * python313-libmount-debuginfo-2.41.1-160000.4.1 * libblkid1-2.41.1-160000.4.1 * util-linux-systemd-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-debuginfo-2.41.1-160000.4.1 * lastlog2-2.41.1-160000.4.1 * util-linux-debugsource-2.41.1-160000.4.1 * python313-libmount-2.41.1-160000.4.1 * lastlog2-debuginfo-2.41.1-160000.4.1 * libmount1-2.41.1-160000.4.1 * libfdisk-devel-static-2.41.1-160000.4.1 * util-linux-systemd-debugsource-2.41.1-160000.4.1 * util-linux-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-2.41.1-160000.4.1 * util-linux-tty-tools-debuginfo-2.41.1-160000.4.1 * libfdisk-devel-2.41.1-160000.4.1 * libfdisk1-debuginfo-2.41.1-160000.4.1 * libblkid-devel-static-2.41.1-160000.4.1 * libsmartcols1-2.41.1-160000.4.1 * util-linux-tty-tools-2.41.1-160000.4.1 * libuuid1-2.41.1-160000.4.1 * libmount-devel-2.41.1-160000.4.1 * libfdisk1-2.41.1-160000.4.1 * liblastlog2-devel-2.41.1-160000.4.1 * util-linux-systemd-2.41.1-160000.4.1 * libblkid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-2.41.1-160000.4.1 * uuidd-2.41.1-160000.4.1 * libmount1-debuginfo-2.41.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * util-linux-lang-2.41.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libsmartcols1-debuginfo-2.41.1-160000.4.1 * uuidd-debuginfo-2.41.1-160000.4.1 * libmount-devel-static-2.41.1-160000.4.1 * util-linux-2.41.1-160000.4.1 * libuuid-devel-2.41.1-160000.4.1 * libuuid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-static-2.41.1-160000.4.1 * libuuid-devel-static-2.41.1-160000.4.1 * python-libmount-debugsource-2.41.1-160000.4.1 * libblkid-devel-2.41.1-160000.4.1 * python313-libmount-debuginfo-2.41.1-160000.4.1 * libblkid1-2.41.1-160000.4.1 * util-linux-systemd-debuginfo-2.41.1-160000.4.1 * lastlog2-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-debuginfo-2.41.1-160000.4.1 * util-linux-debugsource-2.41.1-160000.4.1 * python313-libmount-2.41.1-160000.4.1 * lastlog2-2.41.1-160000.4.1 * libmount1-2.41.1-160000.4.1 * libfdisk-devel-static-2.41.1-160000.4.1 * util-linux-systemd-debugsource-2.41.1-160000.4.1 * util-linux-debuginfo-2.41.1-160000.4.1 * liblastlog2-2-2.41.1-160000.4.1 * util-linux-tty-tools-debuginfo-2.41.1-160000.4.1 * libfdisk-devel-2.41.1-160000.4.1 * libfdisk1-debuginfo-2.41.1-160000.4.1 * libblkid-devel-static-2.41.1-160000.4.1 * libsmartcols1-2.41.1-160000.4.1 * util-linux-tty-tools-2.41.1-160000.4.1 * libuuid1-2.41.1-160000.4.1 * libmount-devel-2.41.1-160000.4.1 * libfdisk1-2.41.1-160000.4.1 * liblastlog2-devel-2.41.1-160000.4.1 * util-linux-systemd-2.41.1-160000.4.1 * libblkid1-debuginfo-2.41.1-160000.4.1 * libsmartcols-devel-2.41.1-160000.4.1 * uuidd-2.41.1-160000.4.1 * libmount1-debuginfo-2.41.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * util-linux-lang-2.41.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27456.html * https://bugzilla.suse.com/show_bug.cgi?id=1261606 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:03 -0000 Subject: SUSE-SU-2026:22331-1: moderate: Security update for rpcbind Message-ID: <178292400308.5373.6666709860259243889@bea6e15a6baf> # Security update for rpcbind Announcement ID: SUSE-SU-2026:22331-1 Release Date: 2026-06-22T14:34:40Z Rating: moderate References: * bsc#1117217 * bsc#1181400 * bsc#1267212 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has three fixes can now be installed. ## Description: This update for rpcbind fixes the following issues * Update to rpcbind 1.2.9 (bsc#1267212) https://lore.kernel.org/linux- nfs/5cad3ab4-d24a-45fa-b1e9-d57b2c47a5e4 at redhat.com/ * rpcinfo: stack buffer overflow in rpcinfo rpcbaddrlist() * rpcbind: Stop unauthenticated oversized allocation in PMAPPROC_CALLIT decode * rpcbind: fix memory leak in read_warmstart() * rpcbind: fix memory leaks in network_init() * rpcbind: fix memory leak in init_transport() * Added -v (print version and compile flags) * rpcinfo: Removed a number of "old-style function definition" warnings * man/rpcbind: Update list of options * Comment out ListenStream=@/run/rpcbind.sock * [nfs/nfs-utils/rpcbind] rpcbind: avoid dereferencing NULL from realloc() * systemd/rpcbind.service.in: Add various hardenings options * man/rpcbind: Add Files section to manpage * Moved rpcbind.lock and default configs to /run instead of /var/run ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1031=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1031=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rpcbind-debugsource-1.2.9-160000.1.1 * rpcbind-1.2.9-160000.1.1 * rpcbind-debuginfo-1.2.9-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rpcbind-debugsource-1.2.9-160000.1.1 * rpcbind-1.2.9-160000.1.1 * rpcbind-debuginfo-1.2.9-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1117217 * https://bugzilla.suse.com/show_bug.cgi?id=1181400 * https://bugzilla.suse.com/show_bug.cgi?id=1267212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:11 -0000 Subject: SUSE-SU-2026:22330-1: important: Security update for perl-DBI Message-ID: <178292401144.5373.1647349474512668958@bea6e15a6baf> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22330-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1267849 * bsc#1267957 Cross-References: * CVE-2026-10879 * CVE-2026-9698 CVSS scores: * CVE-2026-10879 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10879 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10879 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). * CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1041=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1041=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DBI-debugsource-1.647.0-160000.3.1 * perl-DBI-1.647.0-160000.3.1 * perl-DBI-debuginfo-1.647.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.647.0-160000.3.1 * perl-DBI-1.647.0-160000.3.1 * perl-DBI-debuginfo-1.647.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10879.html * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267849 * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:16 -0000 Subject: SUSE-SU-2026:22329-1: important: Security update for perl-Config-IniFiles Message-ID: <178292401694.5373.16755902908216430677@bea6e15a6baf> # Security update for perl-Config-IniFiles Announcement ID: SUSE-SU-2026:22329-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1268236 Cross-References: * CVE-2026-11527 CVSS scores: * CVE-2026-11527 ( SUSE ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-11527 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Config-IniFiles fixes the following issue * CVE-2026-11527: OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle (bsc#1268236). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1024=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1024=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-Config-IniFiles-3.000003-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-Config-IniFiles-3.000003-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11527.html * https://bugzilla.suse.com/show_bug.cgi?id=1268236 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:27 -0000 Subject: SUSE-SU-2026:22328-1: important: Security update for google-cloud-sap-agent Message-ID: <178292402725.5373.2422302555901003700@bea6e15a6baf> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:22328-1 Release Date: 2026-06-22T14:30:38Z Rating: important References: * bsc#1265764 * bsc#1265991 * bsc#1266604 Cross-References: * CVE-2026-33186 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265764). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266604). Changes for google-cloud-sap-agent: * Update to version 3.15 * Remove LoggingClient error failure for hanadiskrestore and hanadiskbackup. * Add checks for unexpected arguments in hanadiskbackup and hanadiskrestore. * Update SAP Agent version to 3.15. * Refactor grubBootLoaderX5 to check for BLS support via grub2-mkconfig help. * Update all go dependencies * Check grub2-mkconfig for BLS support on X4 instances. * Add tenant SID collection to supportbundle. * Update golang.org/x/net dependency. This is to address (#444) * Fork tuned.conf to tuned-x5.conf for X5 series configurations * Enable configureX5 in configureinstance. * Create skeleton implementation and tests for X5 configureinstance support. * Enable detection of x5 machine types in configureinstance * Update to version 3.14 (bsc#1265991) * Update Daemon Restart method to pass the correct cancel function to the new handler. * Remove redundant error logging in HANA disk restore. * Fetch and rename Logical Volume during HANA disk restore. * Add usage metrics for CMEK disk restore. * Add multi-region and global KMS keys location checks. * Convert HANA SID to uppercase in hanadiskbackup and hanadiskrestore. * Log warning instead of erroring out on KMS key get failure. * Initialize GCE client in status onetime command. * Validate presence of KMS key in hanadiskrestore. * Add SID parameter to HANA backup/restore path functions. * Add KMS key location validation for HANA disk restore. * Update agent version to 3.14. * Fixes an issue if there is a whitespace around an argument passed in * Add validation to prevent using both CSEK and KMS keys in hanadiskrestore. * Handle disk recreation in HANA disk restore when IOPS, throughput, size, or KMS key are specified. * Refactor disk restore and configuration logic. * Add support for CMEK encryption of restored disks. * Remove obsolete TODOs. * Update to version 3.13 * Replace strings.TrimSuffix with strings.TrimSpace in hanabackup.go * Improve error messages in hanabackup.go. * Add system state logging and logical device verification. * Minor version bump * Improve SAP instance comparison for process metrics collectors to prevent unnecessary restarts of collectors. * Delete supportbundlehandler package. * Remove configurehandler from sapguestactions. * Delete hanadiskbackuphandler from sapguestactions. * Remove Guest Actions and GCBDR Actions from initial daemon start. * Remove `gsutil` check from collection definition. * Delete performancediagnosticshandler package. * Remove unused handlers and shell command execution. * status feature fixes - pass secret name * Fix an issue in system discovery if discovering a network fails, particularly due to an IAM permission error. * Add verification for HANA data volume state after disk restore. * Error handling for rescanVolumegroups and improved logging. * Add link to What's New page in the sapagent README. * Add secret manager IAM checks if secret key is preset in status ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1022=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1022=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-cloud-sap-agent-3.15-160000.1.1 * google-cloud-sap-agent-debuginfo-3.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-cloud-sap-agent-3.15-160000.1.1 * google-cloud-sap-agent-debuginfo-3.15-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1265764 * https://bugzilla.suse.com/show_bug.cgi?id=1265991 * https://bugzilla.suse.com/show_bug.cgi?id=1266604 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:36 -0000 Subject: SUSE-SU-2026:22326-1: moderate: Security update for keylime Message-ID: <178292403676.5373.12805094789757839395@bea6e15a6baf> # Security update for keylime Announcement ID: SUSE-SU-2026:22326-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1264265 Cross-References: * CVE-2026-6420 CVSS scores: * CVE-2026-6420 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-6420 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2026-6420 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for keylime fixes the following issue * CVE-2026-6420: use of hardcoded challenge nonce for TPM quote attestation allows for security bypass (bsc#1264265). Changes for keylime: * Update to version 7.14.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1037=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 * keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * keylime-tenant-7.14.2-160000.1.1 * keylime-firewalld-7.14.2-160000.1.1 * keylime-tpm_cert_store-7.14.2-160000.1.1 * keylime-config-7.14.2-160000.1.1 * keylime-verifier-7.14.2-160000.1.1 * keylime-logrotate-7.14.2-160000.1.1 * keylime-registrar-7.14.2-160000.1.1 * python313-keylime-7.14.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6420.html * https://bugzilla.suse.com/show_bug.cgi?id=1264265 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:42 -0000 Subject: SUSE-SU-2026:22325-1: moderate: Security update for sed Message-ID: <178292404251.5373.9527666785373688086@bea6e15a6baf> # Security update for sed Announcement ID: SUSE-SU-2026:22325-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1262144 Cross-References: * CVE-2026-5958 CVSS scores: * CVE-2026-5958 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N * CVE-2026-5958 ( SUSE ): 6.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N * CVE-2026-5958 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for sed fixes the following issue * CVE-2026-5958: a TOCTOU race can allow to read attacker-controlled content and write it to an unintended file (bsc#1262144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1036=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1036=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * sed-debuginfo-4.9-160000.3.1 * sed-4.9-160000.3.1 * sed-debugsource-4.9-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * sed-lang-4.9-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * sed-debuginfo-4.9-160000.3.1 * sed-4.9-160000.3.1 * sed-debugsource-4.9-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * sed-lang-4.9-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5958.html * https://bugzilla.suse.com/show_bug.cgi?id=1262144 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:40:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:40:51 -0000 Subject: SUSE-SU-2026:22324-1: moderate: Security update for libexif Message-ID: <178292405113.5373.16423803290768056227@bea6e15a6baf> # Security update for libexif Announcement ID: SUSE-SU-2026:22324-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1259755 * bsc#1262000 * bsc#1262001 Cross-References: * CVE-2026-32775 * CVE-2026-40385 * CVE-2026-40386 CVSS scores: * CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-32775 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for libexif fixes the following issues * CVE-2026-32775: Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755). * CVE-2026-40385: information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000). * CVE-2026-40386: denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1035=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1035=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libexif12-debuginfo-0.6.26-160000.1.1 * libexif12-0.6.26-160000.1.1 * libexif-debugsource-0.6.26-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libexif12-debuginfo-0.6.26-160000.1.1 * libexif12-0.6.26-160000.1.1 * libexif-debugsource-0.6.26-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32775.html * https://www.suse.com/security/cve/CVE-2026-40385.html * https://www.suse.com/security/cve/CVE-2026-40386.html * https://bugzilla.suse.com/show_bug.cgi?id=1259755 * https://bugzilla.suse.com/show_bug.cgi?id=1262000 * https://bugzilla.suse.com/show_bug.cgi?id=1262001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:41:09 -0000 Subject: SUSE-SU-2026:22322-1: moderate: Security update for krb5 Message-ID: <178292406928.5373.3666070320239444135@bea6e15a6baf> # Security update for krb5 Announcement ID: SUSE-SU-2026:22322-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1263366 * bsc#1263367 Cross-References: * CVE-2026-40355 * CVE-2026-40356 CVSS scores: * CVE-2026-40355 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40355 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for krb5 fixes the following issues * CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). * CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1033=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1033=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * krb5-client-1.21.3-160000.3.1 * krb5-plugin-preauth-spake-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-1.21.3-160000.3.1 * krb5-1.21.3-160000.3.1 * krb5-server-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-1.21.3-160000.3.1 * krb5-plugin-preauth-spake-debuginfo-1.21.3-160000.3.1 * krb5-server-debuginfo-1.21.3-160000.3.1 * krb5-devel-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-debuginfo-1.21.3-160000.3.1 * krb5-client-debuginfo-1.21.3-160000.3.1 * krb5-debugsource-1.21.3-160000.3.1 * krb5-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-1.21.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * krb5-plugin-preauth-spake-1.21.3-160000.3.1 * krb5-client-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-1.21.3-160000.3.1 * krb5-server-1.21.3-160000.3.1 * krb5-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-1.21.3-160000.3.1 * krb5-plugin-preauth-spake-debuginfo-1.21.3-160000.3.1 * krb5-devel-1.21.3-160000.3.1 * krb5-server-debuginfo-1.21.3-160000.3.1 * krb5-plugin-kdb-ldap-debuginfo-1.21.3-160000.3.1 * krb5-client-debuginfo-1.21.3-160000.3.1 * krb5-debugsource-1.21.3-160000.3.1 * krb5-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-pkinit-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-debuginfo-1.21.3-160000.3.1 * krb5-plugin-preauth-otp-1.21.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40355.html * https://www.suse.com/security/cve/CVE-2026-40356.html * https://bugzilla.suse.com/show_bug.cgi?id=1263366 * https://bugzilla.suse.com/show_bug.cgi?id=1263367 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:41:14 -0000 Subject: SUSE-SU-2026:22321-1: moderate: Security update for python-click Message-ID: <178292407480.5373.9717622875380729782@bea6e15a6baf> # Security update for python-click Announcement ID: SUSE-SU-2026:22321-1 Release Date: 2026-06-22T14:30:37Z Rating: moderate References: * bsc#1263898 Cross-References: * CVE-2026-7246 CVSS scores: * CVE-2026-7246 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-7246 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-7246 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-7246 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-click fixes the following issue * CVE-2026-7246: Arbitrary command execution via command injection in click.edit() (bsc#1263898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1029=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1029=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-click-8.2.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-click-8.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7246.html * https://bugzilla.suse.com/show_bug.cgi?id=1263898 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:41:22 -0000 Subject: SUSE-SU-2026:22320-1: important: Security update for amazon-ecs-init Message-ID: <178292408292.5373.18219671793095767545@bea6e15a6baf> # Security update for amazon-ecs-init Announcement ID: SUSE-SU-2026:22320-1 Release Date: 2026-06-22T14:30:37Z Rating: important References: * bsc#1265843 * bsc#1266652 Cross-References: * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for amazon-ecs-init fixes the following issues Update to version 1.103.2: * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265843). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266652). Changes: * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/fsx from 1.53.1 to 1.65.10 in /agent (#4966) * Enhancement - Add semgrep security scan for command injection (#4959) * Enhancement - Bump golang.org/x/tools from 0.39.0 to 0.45.0 in /ecs-agent (#4965), also updates x/net to 0.54.0 (bsc#1266652, CVE-2026-39821) * Enhancement - Add integration test for credential refresher (#4961) * Enhancement - Bump golang.org/x/tools from 0.42.0 to 0.45.0 in /agent (#4873) * Enhancement - Update Go version to 1.25.10 (#4960) * Enhancement - Bump go.etcd.io/bbolt from 1.3.9 to 1.4.3 in /ecs-agent (#4872) * Enhancement - update credentials-fetcher retry comments/tests (#4954) * Enhancement - Enhancement - Add retry mechanism to credentialsfetcher (#4948) * Enhancement - Add IMDS credential refresher (#4953) * Bugfix - fix flaky tests depending on timers (#4955) * Feature - Implement IMDS scanner for task credential retrieval, in the shared library (#4945) * Feature - Add config/capability for IMDS-based task credential retrieval (disabled for now) (#4938) * Feature - Add IMDS credential scanner interface and capability constant for IMDS-based task credential retrieval (#4937) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/cloudwatchlogs from 1.47.3 to 1.65.0 in /agent (#4921) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.63.1 to 1.97.3 in /ecs-init (#4923) from 1.79.2 to 1.97.3 in /agent (#4924) * Enhancement - Bump go.opentelemetry.io/otel/exporters/otlp/ otlptrace/ otlptracehttp from 1.32.0 to 1.43.0 in /agent (#4926) * Enhancement - Truncate log values to make agent logs less verbose (#4940) * Enhancement - Golang bump: 1.25.9 (#4935) * Enhancement - Use env variable to read user input when mounting FSx volumes (#4934) * Enhancement - Enhancement - Replace SSM Dualstack endpoint resolution logic with UseDualStackEndpoint (#4931) * Enhancement - Emit duration metrics for TACS connect/disconnect (#4928) * Enhancement - Bump github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream from 1.6.10 to 1.7.8 in /agent (#4922) from 1.6.5 to 1.7.8 in /ecs-init (#4925) * Enhancement - Track and emit metric for disconnect time from ACS (#4920) * Enhancement - engine: skip execution role checks when task desired status is stopped (#4918) * Enhancement - Add NeuronDevices type and sysfs-based device discovery (#4919) * Bugfix - Fix release workflow branch handling and add GitHub App token (#4929) * Bugfix - fix(netlib): Conditionally add IPv6 subnet to IPAM config when IPv6 (#4916) * Enhancement - Update SSM exec agent version to 3.3.4108.0 (#4912) * Enhancement - Update Go version to 1.25.8 (#4894) * Enhancement - Apply skip-gpg-check to both ecs-init and ssm agent (#4901) * Enhancement - Bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#4906) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1025=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1025=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * amazon-ecs-init-1.103.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * amazon-ecs-init-1.103.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1265843 * https://bugzilla.suse.com/show_bug.cgi?id=1266652 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:41:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:41:55 -0000 Subject: SUSE-SU-2026:22319-1: moderate: Security update for dnsdist Message-ID: <178292411572.5373.3562531635734042987@bea6e15a6baf> # Security update for dnsdist Announcement ID: SUSE-SU-2026:22319-1 Release Date: 2026-06-22T14:30:36Z Rating: moderate References: * bsc#1261236 * bsc#1261237 * bsc#1261238 * bsc#1261239 * bsc#1261240 * bsc#1261241 * bsc#1261243 * bsc#1262536 * bsc#1262537 * bsc#1262538 * bsc#1262539 * bsc#1262540 * bsc#1262541 * bsc#1262542 * bsc#1262543 * bsc#1262544 * bsc#1262545 * bsc#1262546 Cross-References: * CVE-2026-0396 * CVE-2026-0397 * CVE-2026-24028 * CVE-2026-24029 * CVE-2026-24030 * CVE-2026-27853 * CVE-2026-27854 * CVE-2026-33254 * CVE-2026-33257 * CVE-2026-33260 * CVE-2026-33593 * CVE-2026-33594 * CVE-2026-33595 * CVE-2026-33596 * CVE-2026-33597 * CVE-2026-33598 * CVE-2026-33599 * CVE-2026-33602 CVSS scores: * CVE-2026-0396 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-0396 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0396 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0397 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-0397 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-0397 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-24028 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24028 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-24029 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-24029 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24029 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-24030 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-24030 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-24030 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27853 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27853 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27854 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27854 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-27854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33254 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33257 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33260 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33260 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33593 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33594 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33595 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33595 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33596 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33596 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33597 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33598 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-33598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33599 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33599 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33602 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33602 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for dnsdist fixes the following issues * CVE-2026-0396: crafted DNS queries can allow to inject HTML content (bsc#1261236). * CVE-2026-0397: CORS misconfiguration can lead to information disclosure (bsc#1261237). * CVE-2026-24028: crafted DNS response packet can lead to an out-of-bounds read (bsc#1261238). * CVE-2026-24029: HTTPS ACL bypass can allow clients to send DoH queries (bsc#1261239). * CVE-2026-24030: allocating too much memory while processing DNS can result in a denial of service (bsc#1261240). * CVE-2026-27853: crafted DNS responses can lead to an out-of-bounds write (bsc#1261241). * CVE-2026-27854: crafted DNS queries can be used to trigger a use-after-free (bsc#1261243). * CVE-2026-33254: Resource exhaustion via DoQ/DoH3 connections (bsc#1262538). * CVE-2026-33257: Insufficient input validation of internal webserver (bsc#1262536). * CVE-2026-33260: Insufficient input validation of internal webserver (bsc#1262537). * CVE-2026-33593: Denial of service via crafted DNSCrypt query (bsc#1262546). * CVE-2026-33594: Outgoing DoH excessive memory allocation (bsc#1262545). * CVE-2026-33595: DoQ/DoH3 excessive memory allocation (bsc#1262544). * CVE-2026-33596: TCP backend stream ID overflow (bsc#1262543). * CVE-2026-33597: PRSD detection denial of service (bsc#1262542). * CVE-2026-33598: Out-of-bounds read in cache inspection via Lua (bsc#1262541). * CVE-2026-33599: Out-of-bounds read in service discovery (bsc#1262540). * CVE-2026-33602: Off-by-one access when processing crafted UDP responses (bsc#1262539). Changes for dnsdist: * Updated to 1.9.13 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1027=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1027=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dnsdist-1.9.13-160000.1.1 * dnsdist-debugsource-1.9.13-160000.1.1 * dnsdist-debuginfo-1.9.13-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dnsdist-1.9.13-160000.1.1 * dnsdist-debugsource-1.9.13-160000.1.1 * dnsdist-debuginfo-1.9.13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0396.html * https://www.suse.com/security/cve/CVE-2026-0397.html * https://www.suse.com/security/cve/CVE-2026-24028.html * https://www.suse.com/security/cve/CVE-2026-24029.html * https://www.suse.com/security/cve/CVE-2026-24030.html * https://www.suse.com/security/cve/CVE-2026-27853.html * https://www.suse.com/security/cve/CVE-2026-27854.html * https://www.suse.com/security/cve/CVE-2026-33254.html * https://www.suse.com/security/cve/CVE-2026-33257.html * https://www.suse.com/security/cve/CVE-2026-33260.html * https://www.suse.com/security/cve/CVE-2026-33593.html * https://www.suse.com/security/cve/CVE-2026-33594.html * https://www.suse.com/security/cve/CVE-2026-33595.html * https://www.suse.com/security/cve/CVE-2026-33596.html * https://www.suse.com/security/cve/CVE-2026-33597.html * https://www.suse.com/security/cve/CVE-2026-33598.html * https://www.suse.com/security/cve/CVE-2026-33599.html * https://www.suse.com/security/cve/CVE-2026-33602.html * https://bugzilla.suse.com/show_bug.cgi?id=1261236 * https://bugzilla.suse.com/show_bug.cgi?id=1261237 * https://bugzilla.suse.com/show_bug.cgi?id=1261238 * https://bugzilla.suse.com/show_bug.cgi?id=1261239 * https://bugzilla.suse.com/show_bug.cgi?id=1261240 * https://bugzilla.suse.com/show_bug.cgi?id=1261241 * https://bugzilla.suse.com/show_bug.cgi?id=1261243 * https://bugzilla.suse.com/show_bug.cgi?id=1262536 * https://bugzilla.suse.com/show_bug.cgi?id=1262537 * https://bugzilla.suse.com/show_bug.cgi?id=1262538 * https://bugzilla.suse.com/show_bug.cgi?id=1262539 * https://bugzilla.suse.com/show_bug.cgi?id=1262540 * https://bugzilla.suse.com/show_bug.cgi?id=1262541 * https://bugzilla.suse.com/show_bug.cgi?id=1262542 * https://bugzilla.suse.com/show_bug.cgi?id=1262543 * https://bugzilla.suse.com/show_bug.cgi?id=1262544 * https://bugzilla.suse.com/show_bug.cgi?id=1262545 * https://bugzilla.suse.com/show_bug.cgi?id=1262546 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:42:39 -0000 Subject: SUSE-SU-2026:22315-1: important: Security update for openssl-3 Message-ID: <178292415997.5373.3799640822053632634@bea6e15a6baf> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22315-1 Release Date: 2026-06-22T12:26:17Z Rating: important References: * bsc#1259652 * bsc#1266340 * bsc#1266341 * bsc#1266342 * bsc#1266344 * bsc#1266345 * bsc#1266347 * bsc#1266349 * bsc#1266350 * bsc#1266351 * bsc#1266352 * bsc#1266353 * bsc#1266355 * bsc#1266356 * bsc#1266357 Cross-References: * CVE-2026-2673 * CVE-2026-34180 * CVE-2026-34182 * CVE-2026-34183 * CVE-2026-42764 * CVE-2026-42766 * CVE-2026-42767 * CVE-2026-42768 * CVE-2026-42769 * CVE-2026-42770 * CVE-2026-45445 * CVE-2026-45446 * CVE-2026-45447 * CVE-2026-7383 * CVE-2026-9076 CVSS scores: * CVE-2026-2673 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-2673 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-2673 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34180 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34180 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34180 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34183 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34183 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34183 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42764 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42764 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42764 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42766 ( SUSE ): 6.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42766 ( SUSE ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42766 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42768 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42768 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N * CVE-2026-42768 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42769 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42769 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42769 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42770 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42770 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42770 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45445 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45445 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45445 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45446 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-45446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-45446 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-45447 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45447 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45447 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7383 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7383 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7383 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9076 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-9076 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-9076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues * CVE-2026-2673: TLS 1.3 servers may choose unexpected key agreement group (bsc#1259652). * CVE-2026-7383: Possible Heap Buffer Overflow in ASN.1 Multibyte String Conversion (bsc#1266340). * CVE-2026-9076: Out-of-Bounds Read in CMS Password-Based Decryption (bsc#1266341). * CVE-2026-34180: Heap Buffer Over-read in ASN.1 Content Parsing (bsc#1266342). * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). * CVE-2026-34183: Unbounded Memory Growth in the QUIC PATH_CHALLENGE Handler (bsc#1266345). * CVE-2026-42764: NULL pointer dereference in QUIC server initial packet handling (bsc#1266347). * CVE-2026-42766: Possible NULL Dereference in Password-Based CMS Decryption (bsc#1266349). * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). * CVE-2026-42768: Multi-RecipientInfo Bleichenbacher Oracle in CMS_decrypt() and PKCS7_decrypt() (bsc#1266351). * CVE-2026-42769: Trust-Anchor Substitution via cert/issuer Typo in CMP rootCaKeyUpdate (bsc#1266352). * CVE-2026-42770: FFC-DH Peer Validation Uses Attacker-Supplied q (bsc#1266353). * CVE-2026-45445: AES-OCB IV Ignored on EVP_Cipher() Path (bsc#1266355). * CVE-2026-45446: Incorrect Tag Processing for Empty Messages in AES-GCM-SIV and AES-SIV modes (bsc#1266356). * CVE-2026-45447: Heap Use-After-Free in OpenSSL PKCS7_verify() (bsc#1266357). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1017=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1017=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openssl-3-debuginfo-3.5.0-160000.8.1 * libopenssl3-3.5.0-160000.8.1 * openssl-3-debugsource-3.5.0-160000.8.1 * libopenssl3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-devel-3.5.0-160000.8.1 * openssl-3-3.5.0-160000.8.1 * libopenssl-3-fips-provider-3.5.0-160000.8.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server 16.0 (noarch) * openssl-3-doc-3.5.0-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openssl-3-debuginfo-3.5.0-160000.8.1 * libopenssl3-3.5.0-160000.8.1 * openssl-3-debugsource-3.5.0-160000.8.1 * libopenssl3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-devel-3.5.0-160000.8.1 * openssl-3-3.5.0-160000.8.1 * libopenssl-3-fips-provider-3.5.0-160000.8.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-3.5.0-160000.8.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.8.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openssl-3-doc-3.5.0-160000.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2673.html * https://www.suse.com/security/cve/CVE-2026-34180.html * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-34183.html * https://www.suse.com/security/cve/CVE-2026-42764.html * https://www.suse.com/security/cve/CVE-2026-42766.html * https://www.suse.com/security/cve/CVE-2026-42767.html * https://www.suse.com/security/cve/CVE-2026-42768.html * https://www.suse.com/security/cve/CVE-2026-42769.html * https://www.suse.com/security/cve/CVE-2026-42770.html * https://www.suse.com/security/cve/CVE-2026-45445.html * https://www.suse.com/security/cve/CVE-2026-45446.html * https://www.suse.com/security/cve/CVE-2026-45447.html * https://www.suse.com/security/cve/CVE-2026-7383.html * https://www.suse.com/security/cve/CVE-2026-9076.html * https://bugzilla.suse.com/show_bug.cgi?id=1259652 * https://bugzilla.suse.com/show_bug.cgi?id=1266340 * https://bugzilla.suse.com/show_bug.cgi?id=1266341 * https://bugzilla.suse.com/show_bug.cgi?id=1266342 * https://bugzilla.suse.com/show_bug.cgi?id=1266344 * https://bugzilla.suse.com/show_bug.cgi?id=1266345 * https://bugzilla.suse.com/show_bug.cgi?id=1266347 * https://bugzilla.suse.com/show_bug.cgi?id=1266349 * https://bugzilla.suse.com/show_bug.cgi?id=1266350 * https://bugzilla.suse.com/show_bug.cgi?id=1266351 * https://bugzilla.suse.com/show_bug.cgi?id=1266352 * https://bugzilla.suse.com/show_bug.cgi?id=1266353 * https://bugzilla.suse.com/show_bug.cgi?id=1266355 * https://bugzilla.suse.com/show_bug.cgi?id=1266356 * https://bugzilla.suse.com/show_bug.cgi?id=1266357 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:42:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:42:49 -0000 Subject: SUSE-SU-2026:22313-1: important: Security update for gsasl Message-ID: <178292416946.5373.4682650474439931425@bea6e15a6baf> # Security update for gsasl Announcement ID: SUSE-SU-2026:22313-1 Release Date: 2026-06-22T09:25:40Z Rating: important References: * bsc#1266371 Cross-References: * CVE-2026-48829 CVSS scores: * CVE-2026-48829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gsasl fixes the following issues: Changes in gsasl: * CVE-2026-48829: DIGEST-MD5: Fix NULL pointer dereference in parser (bsc#1266371) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1016=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1016=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gsasl-devel-2.2.1-160000.3.1 * gsasl-debugsource-2.2.1-160000.3.1 * gsasl-debuginfo-2.2.1-160000.3.1 * libgsasl18-2.2.1-160000.3.1 * gsasl-2.2.1-160000.3.1 * libgsasl18-debuginfo-2.2.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gsasl-lang-2.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gsasl-devel-2.2.1-160000.3.1 * gsasl-debugsource-2.2.1-160000.3.1 * gsasl-debuginfo-2.2.1-160000.3.1 * libgsasl18-2.2.1-160000.3.1 * gsasl-2.2.1-160000.3.1 * libgsasl18-debuginfo-2.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gsasl-lang-2.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48829.html * https://bugzilla.suse.com/show_bug.cgi?id=1266371 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:43:45 -0000 Subject: SUSE-SU-2026:22306-1: important: Security update for tiff Message-ID: <178292422516.5373.4037322864039966616@bea6e15a6baf> # Security update for tiff Announcement ID: SUSE-SU-2026:22306-1 Release Date: 2026-06-21T02:12:54Z Rating: important References: * bsc#1248278 * bsc#1257123 * bsc#1260411 Cross-References: * CVE-2018-7456 * CVE-2023-0800 * CVE-2023-0801 * CVE-2023-0802 * CVE-2023-0803 * CVE-2023-0804 * CVE-2025-8851 * CVE-2026-4775 CVSS scores: * CVE-2018-7456 ( SUSE ): 5.5 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2018-7456 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0800 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0800 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0800 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0801 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0801 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0801 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0802 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0802 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0802 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0803 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0803 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-0803 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0804 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2023-0804 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2023-0804 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8851 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-8851 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2025-8851 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8851 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues Security issues: * CVE-2025-8851: libtiff: LibTIFF Stack-based buffer overflow (bsc#1248278). * CVE-2026-4775: signed integer overflow in the `putcontig8bitYCbCr44tile` function (bsc#1260411). Non security issue: * QGIS can't export with GDAL- LERC codec, LERC library not found anywhere in the system (bsc#1257123). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1007=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1007=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libtiff6-4.7.1-160000.2.1 * libtiff-devel-4.7.1-160000.2.1 * libtiff6-debuginfo-4.7.1-160000.2.1 * tiff-debugsource-4.7.1-160000.2.1 * tiff-debuginfo-4.7.1-160000.2.1 * tiff-4.7.1-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libtiff6-4.7.1-160000.2.1 * libtiff-devel-4.7.1-160000.2.1 * libtiff6-debuginfo-4.7.1-160000.2.1 * tiff-debugsource-4.7.1-160000.2.1 * tiff-debuginfo-4.7.1-160000.2.1 * tiff-4.7.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2018-7456.html * https://www.suse.com/security/cve/CVE-2023-0800.html * https://www.suse.com/security/cve/CVE-2023-0801.html * https://www.suse.com/security/cve/CVE-2023-0802.html * https://www.suse.com/security/cve/CVE-2023-0803.html * https://www.suse.com/security/cve/CVE-2023-0804.html * https://www.suse.com/security/cve/CVE-2025-8851.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1248278 * https://bugzilla.suse.com/show_bug.cgi?id=1257123 * https://bugzilla.suse.com/show_bug.cgi?id=1260411 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:43:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:43:51 -0000 Subject: SUSE-SU-2026:22305-1: important: Security update for helm Message-ID: <178292423159.5373.139680770047492976@bea6e15a6baf> # Security update for helm Announcement ID: SUSE-SU-2026:22305-1 Release Date: 2026-06-21T00:44:54Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1006=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1006=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * helm-zsh-completion-3.21.1-160000.1.2 * helm-fish-completion-3.21.1-160000.1.1 * helm-zsh-completion-3.21.1-160000.1.1 * helm-bash-completion-3.21.1-160000.1.1 * helm-fish-completion-3.21.1-160000.1.2 * helm-bash-completion-3.21.1-160000.1.2 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * helm-3.21.1-160000.1.1 * helm-debuginfo-3.21.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (s390x) * helm-debuginfo-3.21.1-160000.1.2 * helm-3.21.1-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * helm-3.21.1-160000.1.1 * helm-debuginfo-3.21.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-fish-completion-3.21.1-160000.1.1 * helm-zsh-completion-3.21.1-160000.1.1 * helm-bash-completion-3.21.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:44:09 -0000 Subject: SUSE-SU-2026:22302-1: moderate: Security update for glycin-loaders Message-ID: <178292424971.5373.969005902886986481@bea6e15a6baf> # Security update for glycin-loaders Announcement ID: SUSE-SU-2026:22302-1 Release Date: 2026-06-20T18:27:34Z Rating: moderate References: * bsc#1248035 * bsc#1249010 Cross-References: * CVE-2025-55159 * CVE-2025-58160 CVSS scores: * CVE-2025-55159 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-55159 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2025-55159 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for glycin-loaders fixes the following issues * CVE-2025-55159: slab: incorrect bounds check in get_disjoint_mut function can lead to undefined behavior or potential crash due to out-of-bounds access (bsc#1248035). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249010). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-999=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-GlyGtk4_1-1.2.1-160000.3.1 * libglycin-1-0-1.2.1-160000.3.1 * typelib-1_0-Gly_1-1.2.1-160000.3.1 * glycin-loaders-1.2.1-160000.3.1 * libglycin-gtk4-1-0-1.2.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55159.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1248035 * https://bugzilla.suse.com/show_bug.cgi?id=1249010 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:44:21 -0000 Subject: SUSE-SU-2026:22300-1: important: Security update for python-pip Message-ID: <178292426105.5373.7238441493152280783@bea6e15a6baf> # Security update for python-pip Announcement ID: SUSE-SU-2026:22300-1 Release Date: 2026-06-20T18:17:57Z Rating: important References: * bsc#1266669 Cross-References: * CVE-2026-8643 CVSS scores: * CVE-2026-8643 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-8643 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8643 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8643 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-pip fixes the following issue * CVE-2026-8643: Path traversal via malicious entry point name in pip wheel installation allows arbitrary file overwrite (bsc#1266669). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1005=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1005=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-pip-25.0.1-160000.5.1 * python313-pip-wheel-25.0.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-pip-25.0.1-160000.5.1 * python313-pip-wheel-25.0.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8643.html * https://bugzilla.suse.com/show_bug.cgi?id=1266669 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:44:38 -0000 Subject: SUSE-SU-2026:22297-1: moderate: Security update for glib-networking Message-ID: <178292427843.5373.476289142643205677@bea6e15a6baf> # Security update for glib-networking Announcement ID: SUSE-SU-2026:22297-1 Release Date: 2026-06-20T18:14:55Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-995=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-995=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * glib-networking-debugsource-2.80.1-160000.3.1 * glib-networking-2.80.1-160000.3.1 * glib-networking-debuginfo-2.80.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * glib-networking-lang-2.80.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * glib-networking-lang-2.80.1-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * glib-networking-debugsource-2.80.1-160000.3.1 * glib-networking-2.80.1-160000.3.1 * glib-networking-debuginfo-2.80.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:44:51 -0000 Subject: SUSE-SU-2026:22294-1: moderate: Security update for ncurses Message-ID: <178292429187.5373.12515621097568100627@bea6e15a6baf> # Security update for ncurses Announcement ID: SUSE-SU-2026:22294-1 Release Date: 2026-06-20T18:11:34Z Rating: moderate References: * bsc#1259924 Cross-References: * CVE-2025-69720 CVSS scores: * CVE-2025-69720 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-69720 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2025-69720 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-69720 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2025-69720 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for ncurses fixes the following issue: * CVE-2025-69720: buffer overflow in function `analyze_string()`of `progs/infocmp.c` (bsc#1259924). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1004=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1004=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * terminfo-screen-6.5.20250531-160000.3.1 * ncurses-devel-debuginfo-6.5.20250531-160000.3.1 * ncurses-examples-debuginfo-6.5.20250531-160000.3.1 * ncurses-utils-6.5.20250531-160000.3.1 * ncurses-devel-6.5.20250531-160000.3.1 * libncurses5-6.5.20250531-160000.3.1 * libncurses5-debuginfo-6.5.20250531-160000.3.1 * ncurses-examples-6.5.20250531-160000.3.1 * ncurses-debugsource-6.5.20250531-160000.3.1 * libncurses6-debuginfo-6.5.20250531-160000.3.1 * libncurses6-6.5.20250531-160000.3.1 * terminfo-iterm-6.5.20250531-160000.3.1 * tack-1.11.20250503-160000.3.1 * tack-debuginfo-1.11.20250503-160000.3.1 * terminfo-6.5.20250531-160000.3.1 * terminfo-base-6.5.20250531-160000.3.1 * ncurses-utils-debuginfo-6.5.20250531-160000.3.1 * ncurses-devel-static-6.5.20250531-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * terminfo-screen-6.5.20250531-160000.3.1 * ncurses-examples-debuginfo-6.5.20250531-160000.3.1 * ncurses-devel-debuginfo-6.5.20250531-160000.3.1 * ncurses-utils-6.5.20250531-160000.3.1 * ncurses-devel-6.5.20250531-160000.3.1 * ncurses-examples-6.5.20250531-160000.3.1 * libncurses5-debuginfo-6.5.20250531-160000.3.1 * libncurses5-6.5.20250531-160000.3.1 * ncurses-debugsource-6.5.20250531-160000.3.1 * libncurses6-debuginfo-6.5.20250531-160000.3.1 * libncurses6-6.5.20250531-160000.3.1 * terminfo-iterm-6.5.20250531-160000.3.1 * tack-1.11.20250503-160000.3.1 * tack-debuginfo-1.11.20250503-160000.3.1 * terminfo-6.5.20250531-160000.3.1 * terminfo-base-6.5.20250531-160000.3.1 * ncurses-utils-debuginfo-6.5.20250531-160000.3.1 * ncurses-devel-static-6.5.20250531-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-69720.html * https://bugzilla.suse.com/show_bug.cgi?id=1259924 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:44:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:44:57 -0000 Subject: SUSE-SU-2026:2719-1: important: Security update for pacemaker Message-ID: <178292429742.5373.747146413916395563@bea6e15a6baf> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2719-1 Release Date: 2026-07-01T11:33:19Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial-of-service via integer overflow in remote message decompression (bsc#1268381). Changes for pacemaker: * Update to version 2.1.10+20260618.4bca25e3c1: * libcrmcommon: Add additional checks to pcmk__remote_message_xml. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcib: Remove an unnecessary coverity suppression. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix an integer overflow in pcmk__remote_send_xml. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Limit the max size of a remote message. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix integer overflow in remote message code. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Add sanity checks to localized_remote_header. (Crh#2462817, gh#ClusterLabs/pacemaker#4133) * libcrmcommon: Fix a glib logging build error * libcrmcommon, libpacemaker: Don't assign const char * to char * ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2719=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * pacemaker-cli-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-remote-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-cli-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-remote-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-libs-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-debugsource-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-libs-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-devel-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-debuginfo-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (noarch) * pacemaker-schemas-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * python3-pacemaker-2.1.10+20260618.4bca25e3c1-150700.3.6.1 * pacemaker-cts-2.1.10+20260618.4bca25e3c1-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 16:45:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 16:45:09 -0000 Subject: SUSE-SU-2026:2718-1: moderate: Security update for cups Message-ID: <178292430958.5373.9078384410238994897@bea6e15a6baf> # Security update for cups Announcement ID: SUSE-SU-2026:2718-1 Release Date: 2026-07-01T10:23:34Z Rating: moderate References: * bsc#1261569 * bsc#1261570 * bsc#1261571 * bsc#1261572 * bsc#1261742 Cross-References: * CVE-2026-27447 * CVE-2026-34978 * CVE-2026-34979 * CVE-2026-34980 * CVE-2026-39316 CVSS scores: * CVE-2026-27447 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N * CVE-2026-34978 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34978 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34979 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34979 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34980 ( SUSE ): 6.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-34980 ( NVD ): 6.1 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34980 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39316 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39316 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for cups fixes the following issues * CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). * CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). * CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). * CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). * CVE-2026-39316: dangling subscription pointer can lead to a denial of service (bsc#1261742). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2718=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cups-libs-debuginfo-32bit-1.7.5-20.67.1 * cups-debugsource-1.7.5-20.67.1 * cups-client-1.7.5-20.67.1 * cups-libs-32bit-1.7.5-20.67.1 * cups-libs-1.7.5-20.67.1 * cups-devel-1.7.5-20.67.1 * cups-debuginfo-1.7.5-20.67.1 * cups-libs-debuginfo-1.7.5-20.67.1 * cups-1.7.5-20.67.1 * cups-client-debuginfo-1.7.5-20.67.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27447.html * https://www.suse.com/security/cve/CVE-2026-34978.html * https://www.suse.com/security/cve/CVE-2026-34979.html * https://www.suse.com/security/cve/CVE-2026-34980.html * https://www.suse.com/security/cve/CVE-2026-39316.html * https://bugzilla.suse.com/show_bug.cgi?id=1261569 * https://bugzilla.suse.com/show_bug.cgi?id=1261570 * https://bugzilla.suse.com/show_bug.cgi?id=1261571 * https://bugzilla.suse.com/show_bug.cgi?id=1261572 * https://bugzilla.suse.com/show_bug.cgi?id=1261742 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 20:33:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 20:33:16 -0000 Subject: SUSE-SU-2026:2722-1: important: Security update for the Linux Kernel Message-ID: <178293799616.141.6465309689348424886@c0b3d623d882> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2722-1 Release Date: 2026-07-01T13:35:37Z Rating: important References: * bsc#1256668 * bsc#1260531 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263057 * bsc#1263123 * bsc#1263124 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264137 * bsc#1264239 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266840 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267251 * bsc#1267361 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267651 * bsc#1267654 * bsc#1267685 * bsc#1267744 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-23392 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31592 * CVE-2026-31593 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23392 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23392 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31593 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31593 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31593 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 66 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23392: netfilter: nf_tables: release flowtable after rcu grace period on error (bsc#1260531). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already- launched/encrypted vCPU (bsc#1263124). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * ice: ptp: do not WARN when controlling PF is unavailable (bsc#1267251). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * scripts/submit_branch: add SLE15-SP7 submission script * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2722=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2722=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2722=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-2722=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2722=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2722=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2722=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.63.1 * kernel-default-livepatch-6.4.0-150700.53.63.1 * kernel-livepatch-SLE15-SP7_Update_17-debugsource-1-150700.15.3.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * kernel-livepatch-6_4_0-150700_53_63-default-1-150700.15.3.1 * kernel-default-livepatch-devel-6.4.0-150700.53.63.1 * kernel-livepatch-6_4_0-150700_53_63-default-debuginfo-1-150700.15.3.1 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * gfs2-kmp-default-6.4.0-150700.53.63.1 * dlm-kmp-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debugsource-6.4.0-150700.53.63.1 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.63.1 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * ocfs2-kmp-default-6.4.0-150700.53.63.1 * cluster-md-kmp-default-6.4.0-150700.53.63.1 * dlm-kmp-default-6.4.0-150700.53.63.1 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.63.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debugsource-6.4.0-150700.53.63.1 * kernel-default-devel-6.4.0-150700.53.63.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.63.1.150700.17.37.1 * Basesystem Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (noarch) * kernel-devel-6.4.0-150700.53.63.1 * kernel-macros-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debuginfo-6.4.0-150700.53.63.1 * kernel-zfcpdump-debugsource-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-devel-6.4.0-150700.53.63.1 * kernel-64kb-debuginfo-6.4.0-150700.53.63.1 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.63.1 * kernel-64kb-debugsource-6.4.0-150700.53.63.1 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.63.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-debugsource-6.4.0-150700.53.63.1 * reiserfs-kmp-default-6.4.0-150700.53.63.1 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.63.1 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-debugsource-6.4.0-150700.53.63.1 * kernel-azure-devel-6.4.0-150700.53.63.1 * kernel-azure-debuginfo-6.4.0-150700.53.63.1 * kernel-azure-devel-debuginfo-6.4.0-150700.53.63.1 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.63.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150700.53.63.1 * kernel-obs-build-debugsource-6.4.0-150700.53.63.1 * kernel-syms-6.4.0-150700.53.63.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.63.1 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.63.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.63.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-debugsource-6.4.0-150700.53.63.1 * kernel-default-debuginfo-6.4.0-150700.53.63.1 * kernel-default-extra-debuginfo-6.4.0-150700.53.63.1 * kernel-default-extra-6.4.0-150700.53.63.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23392.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31593.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1260531 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263124 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 20:33:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 20:33:23 -0000 Subject: SUSE-SU-2026:2721-1: important: Security update for dracut Message-ID: <178293800357.141.13822405188109765711@c0b3d623d882> # Security update for dracut Announcement ID: SUSE-SU-2026:2721-1 Release Date: 2026-07-01T13:15:53Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 055+suse.402.g2720eea: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2721=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2721=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2721=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2721=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2721=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2721=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-tools-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * dracut-extra-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dracut-fips-055+suse.402.g2720eea-150500.3.41.1 * dracut-debugsource-055+suse.402.g2720eea-150500.3.41.1 * dracut-debuginfo-055+suse.402.g2720eea-150500.3.41.1 * dracut-mkinitrd-deprecated-055+suse.402.g2720eea-150500.3.41.1 * dracut-055+suse.402.g2720eea-150500.3.41.1 * dracut-ima-055+suse.402.g2720eea-150500.3.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 1 20:33:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 01 Jul 2026 20:33:29 -0000 Subject: SUSE-SU-2026:2720-1: important: Security update for dracut Message-ID: <178293800973.141.17137544882542826571@c0b3d623d882> # Security update for dracut Announcement ID: SUSE-SU-2026:2720-1 Release Date: 2026-07-01T13:15:19Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 055+suse.365.g79144c5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2720=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2720=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2720=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2720=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2720=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2720=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2720=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2720=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2720=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * dracut-extra-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-tools-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dracut-mkinitrd-deprecated-055+suse.365.g79144c5-150400.3.49.1 * dracut-055+suse.365.g79144c5-150400.3.49.1 * dracut-debuginfo-055+suse.365.g79144c5-150400.3.49.1 * dracut-fips-055+suse.365.g79144c5-150400.3.49.1 * dracut-ima-055+suse.365.g79144c5-150400.3.49.1 * dracut-debugsource-055+suse.365.g79144c5-150400.3.49.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 08:30:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 02 Jul 2026 08:30:11 -0000 Subject: SUSE-SU-2026:2724-1: moderate: Security update for python-python-dotenv Message-ID: <178298101162.204.4088488860176716165@373793e7b316> # Security update for python-python-dotenv Announcement ID: SUSE-SU-2026:2724-1 Release Date: 2026-07-01T18:09:54Z Rating: moderate References: * bsc#1262423 Cross-References: * CVE-2026-28684 CVSS scores: * CVE-2026-28684 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-28684 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2026-28684 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-python-dotenv fixes the following issue: * CVE-2026-28684: follow symbolic links when rewriting `.env` files (bsc#1262423) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2724=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2724=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 * openSUSE Leap 15.4 (noarch) * python311-python-dotenv-1.0.0-150400.9.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28684.html * https://bugzilla.suse.com/show_bug.cgi?id=1262423 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 08:30:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 02 Jul 2026 08:30:21 -0000 Subject: SUSE-SU-2026:2723-1: moderate: Security update for python311 Message-ID: <178298102109.204.5334611857277401186@373793e7b316> # Security update for python311 Announcement ID: SUSE-SU-2026:2723-1 Release Date: 2026-07-01T18:09:22Z Rating: moderate References: * bsc#1258364 * bsc#1261970 Cross-References: * CVE-2026-3446 CVSS scores: * CVE-2026-3446 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-3446 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-3446 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python311 fixes the following issues: Security issues fixed: * CVE-2026-3446: base64 decoding stops at first padded quad by default and ignores other information that could be processed (bsc#1261970). Other updates and bugfixes: * Rewrite structure of Python interpreter packages. `python3*` symbols should be now provided by real `python3` packages and its subpackages instead of the virtual provides (bsc#1258364). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2723=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2723=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-core-debugsource-3.11.15-150400.9.88.1 * python311-testsuite-3.11.15-150400.9.88.1 * python311-curses-debuginfo-3.11.15-150400.9.88.1 * python311-doc-devhelp-3.11.15-150400.9.88.1 * python311-dbm-3.11.15-150400.9.88.1 * python311-testsuite-debuginfo-3.11.15-150400.9.88.1 * python311-idle-3.11.15-150400.9.88.1 * python311-debugsource-3.11.15-150400.9.88.1 * python311-tools-3.11.15-150400.9.88.1 * libpython3_11-1_0-3.11.15-150400.9.88.1 * python311-base-3.11.15-150400.9.88.1 * python311-doc-3.11.15-150400.9.88.1 * python311-curses-3.11.15-150400.9.88.1 * python311-devel-3.11.15-150400.9.88.1 * libpython3_11-1_0-debuginfo-3.11.15-150400.9.88.1 * python311-3.11.15-150400.9.88.1 * python311-tk-debuginfo-3.11.15-150400.9.88.1 * python311-tk-3.11.15-150400.9.88.1 * python311-dbm-debuginfo-3.11.15-150400.9.88.1 * python311-debuginfo-3.11.15-150400.9.88.1 * python311-base-debuginfo-3.11.15-150400.9.88.1 * openSUSE Leap 15.4 (x86_64) * libpython3_11-1_0-32bit-debuginfo-3.11.15-150400.9.88.1 * python311-32bit-debuginfo-3.11.15-150400.9.88.1 * python311-base-32bit-debuginfo-3.11.15-150400.9.88.1 * python311-32bit-3.11.15-150400.9.88.1 * libpython3_11-1_0-32bit-3.11.15-150400.9.88.1 * python311-base-32bit-3.11.15-150400.9.88.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpython3_11-1_0-64bit-debuginfo-3.11.15-150400.9.88.1 * python311-base-64bit-debuginfo-3.11.15-150400.9.88.1 * python311-64bit-3.11.15-150400.9.88.1 * libpython3_11-1_0-64bit-3.11.15-150400.9.88.1 * python311-64bit-debuginfo-3.11.15-150400.9.88.1 * python311-base-64bit-3.11.15-150400.9.88.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-base-3.11.15-150400.9.88.1 * python311-3.11.15-150400.9.88.1 * libpython3_11-1_0-3.11.15-150400.9.88.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3446.html * https://bugzilla.suse.com/show_bug.cgi?id=1258364 * https://bugzilla.suse.com/show_bug.cgi?id=1261970 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 20:30:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 02 Jul 2026 20:30:10 -0000 Subject: SUSE-SU-2026:2727-1: important: Security update for gstreamer-plugins-good Message-ID: <178302421083.377.1978688873417190271@1451accf52c7> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2727-1 Release Date: 2026-07-02T14:04:42Z Rating: important References: * bsc#1234421 * bsc#1268449 Cross-References: * CVE-2024-47540 * CVE-2026-53705 CVSS scores: * CVE-2024-47540 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2024-47540 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-47540 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issues * CVE-2024-47540: uninitialized stack memory in Matroska/WebM demuxer (bsc#1234421). * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2727=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2727=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.8.3-16.19.1 * gstreamer-plugins-good-1.8.3-16.19.1 * gstreamer-plugins-good-debuginfo-1.8.3-16.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * gstreamer-plugins-good-lang-1.8.3-16.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gstreamer-plugins-good-debugsource-1.8.3-16.19.1 * gstreamer-plugins-good-1.8.3-16.19.1 * gstreamer-plugins-good-debuginfo-1.8.3-16.19.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * gstreamer-plugins-good-lang-1.8.3-16.19.1 ## References: * https://www.suse.com/security/cve/CVE-2024-47540.html * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1234421 * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 20:30:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 02 Jul 2026 20:30:19 -0000 Subject: SUSE-SU-2026:2726-1: important: Security update for python-tornado Message-ID: <178302421977.377.16399165496566543251@1451accf52c7> # Security update for python-tornado Announcement ID: SUSE-SU-2026:2726-1 Release Date: 2026-07-02T13:55:02Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2726=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2726=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2726=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2726=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2726=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2726=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2726=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2726=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2726=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2726=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2726=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2726=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2726=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2726=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2726=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2726=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python3-tornado-4.5.3-150000.3.22.1 * python-tornado-debuginfo-4.5.3-150000.3.22.1 * python-tornado-debugsource-4.5.3-150000.3.22.1 * python3-tornado-debuginfo-4.5.3-150000.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 2 20:30:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 02 Jul 2026 20:30:30 -0000 Subject: SUSE-SU-2026:2725-1: important: Security update for python-tornado6 Message-ID: <178302423035.377.2761718625991209843@1451accf52c7> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:2725-1 Release Date: 2026-07-02T13:52:50Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2725=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2725=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2725=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2725=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2725=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2725=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2725=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.18.1 * python-tornado6-debugsource-6.3.2-150400.9.18.1 * python311-tornado6-6.3.2-150400.9.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:30:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:30:14 -0000 Subject: SUSE-SU-2026:22438-1: moderate: Security update for libssh2_org Message-ID: <178306741487.117.14531966394028636270@2afce7b7fe24> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:22438-1 Release Date: 2026-07-01T09:39:44Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-775=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libssh2_org-debugsource-1.11.0-3.1 * libssh2-1-debuginfo-1.11.0-3.1 * libssh2-1-1.11.0-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:30:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:30:22 -0000 Subject: SUSE-SU-2026:22437-1: moderate: Security update for openssl-3 Message-ID: <178306742214.117.13732986270431288399@2afce7b7fe24> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22437-1 Release Date: 2026-07-01T09:35:35Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-776=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * openssl-3-debuginfo-3.1.4-15.1 * openssl-3-3.1.4-15.1 * libopenssl-3-devel-3.1.4-15.1 * libopenssl3-debuginfo-3.1.4-15.1 * openssl-3-debugsource-3.1.4-15.1 * libopenssl-3-fips-provider-3.1.4-15.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-15.1 * libopenssl3-3.1.4-15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:32:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:32:12 -0000 Subject: SUSE-SU-2026:22436-1: important: Security update for the Linux Kernel Message-ID: <178306753255.117.17746485586275472597@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22436-1 Release Date: 2026-06-30T23:13:02Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-496=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kernel-default-debuginfo-6.4.0-48.1 * kernel-default-debugsource-6.4.0-48.1 * SUSE Linux Micro 6.0 (aarch64 x86_64) * kernel-default-base-6.4.0-48.1.21.25 * SUSE Linux Micro 6.0 (aarch64 nosrc s390x x86_64) * kernel-default-6.4.0-48.1 * SUSE Linux Micro 6.0 (noarch) * kernel-macros-6.4.0-48.1 * kernel-devel-6.4.0-48.1 * kernel-source-6.4.0-48.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-kvmsmall-6.4.0-48.1 * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-default-livepatch-6.4.0-48.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-kvmsmall-debuginfo-6.4.0-48.1 * kernel-kvmsmall-debugsource-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:36:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:36:47 -0000 Subject: SUSE-SU-2026:22433-1: important: Security update for the Linux Kernel Message-ID: <178306780784.117.9057183409049045971@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22433-1 Release Date: 2026-06-30T17:26:45Z Rating: important References: * bsc#1248235 * bsc#1255416 * bsc#1256668 * bsc#1258538 * bsc#1260502 * bsc#1260584 * bsc#1261256 * bsc#1261619 * bsc#1261791 * bsc#1262085 * bsc#1262392 * bsc#1262606 * bsc#1262615 * bsc#1262617 * bsc#1262619 * bsc#1262620 * bsc#1262622 * bsc#1262624 * bsc#1262634 * bsc#1262649 * bsc#1262656 * bsc#1262663 * bsc#1262668 * bsc#1262674 * bsc#1262748 * bsc#1262755 * bsc#1262798 * bsc#1262993 * bsc#1263006 * bsc#1263068 * bsc#1263115 * bsc#1263123 * bsc#1263137 * bsc#1263143 * bsc#1263152 * bsc#1263178 * bsc#1263319 * bsc#1263562 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263724 * bsc#1263769 * bsc#1263774 * bsc#1263790 * bsc#1263879 * bsc#1263880 * bsc#1263883 * bsc#1263930 * bsc#1263932 * bsc#1263934 * bsc#1263945 * bsc#1263993 * bsc#1263996 * bsc#1264000 * bsc#1264011 * bsc#1264045 * bsc#1264063 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264093 * bsc#1264116 * bsc#1264124 * bsc#1264137 * bsc#1264145 * bsc#1264184 * bsc#1264239 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264263 * bsc#1264266 * bsc#1264300 * bsc#1264409 * bsc#1264430 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264476 * bsc#1264484 * bsc#1264549 * bsc#1264551 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264669 * bsc#1264671 * bsc#1264672 * bsc#1264716 * bsc#1264719 * bsc#1264720 * bsc#1264722 * bsc#1264726 * bsc#1264741 * bsc#1264763 * bsc#1264765 * bsc#1264805 * bsc#1264989 * bsc#1265020 * bsc#1265044 * bsc#1265073 * bsc#1265103 * bsc#1265110 * bsc#1265128 * bsc#1265143 * bsc#1265170 * bsc#1265240 * bsc#1265579 * bsc#1265628 * bsc#1265928 * bsc#1265960 * bsc#1266001 * bsc#1266009 * bsc#1266214 * bsc#1266238 * bsc#1266290 * bsc#1266307 * bsc#1266390 * bsc#1266394 * bsc#1266395 * bsc#1266397 * bsc#1266400 * bsc#1266402 * bsc#1266414 * bsc#1266452 * bsc#1266696 * bsc#1266697 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266711 * bsc#1266720 * bsc#1266759 * bsc#1266765 * bsc#1266767 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266878 * bsc#1266889 * bsc#1266895 * bsc#1266901 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266927 * bsc#1266933 * bsc#1266969 * bsc#1266972 * bsc#1267205 * bsc#1267208 * bsc#1267214 * bsc#1267218 * bsc#1267220 * bsc#1267222 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267531 * bsc#1267621 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267652 * bsc#1267654 * bsc#1267663 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267726 * bsc#1267732 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-38549 * CVE-2025-68324 * CVE-2025-68822 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23359 * CVE-2026-23438 * CVE-2026-23444 * CVE-2026-31396 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31464 * CVE-2026-31469 * CVE-2026-31473 * CVE-2026-31480 * CVE-2026-31492 * CVE-2026-31493 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-3150 * CVE-2026-31500 * CVE-2026-31516 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31555 * CVE-2026-31590 * CVE-2026-31592 * CVE-2026-31596 * CVE-2026-31613 * CVE-2026-31614 * CVE-2026-31629 * CVE-2026-31655 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31671 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31678 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31703 * CVE-2026-31752 * CVE-2026-31758 * CVE-2026-31759 * CVE-2026-31767 * CVE-2026-31771 * CVE-2026-43013 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43026 * CVE-2026-43028 * CVE-2026-43030 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43040 * CVE-2026-43049 * CVE-2026-43052 * CVE-2026-43053 * CVE-2026-43054 * CVE-2026-43059 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43109 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43206 * CVE-2026-43234 * CVE-2026-43239 * CVE-2026-43249 * CVE-2026-43252 * CVE-2026-43261 * CVE-2026-43284 * CVE-2026-43296 * CVE-2026-43325 * CVE-2026-43333 * CVE-2026-43338 * CVE-2026-43339 * CVE-2026-43341 * CVE-2026-43345 * CVE-2026-43359 * CVE-2026-43360 * CVE-2026-43361 * CVE-2026-43362 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43411 * CVE-2026-43413 * CVE-2026-43414 * CVE-2026-43455 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43483 * CVE-2026-43491 * CVE-2026-43499 * CVE-2026-43501 * CVE-2026-43503 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45842 * CVE-2026-45843 * CVE-2026-45846 * CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45878 * CVE-2026-45886 * CVE-2026-45894 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45970 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45984 * CVE-2026-46004 * CVE-2026-46005 * CVE-2026-46021 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46043 * CVE-2026-46079 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46101 * CVE-2026-46110 * CVE-2026-46111 * CVE-2026-46113 * CVE-2026-46114 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46157 * CVE-2026-46159 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46197 * CVE-2026-46209 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-38549 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-38549 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-38549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23359 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23359 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23359 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31464 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31464 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31464 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31473 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31480 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31480 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31493 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31493 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3150 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3150 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31516 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31613 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31613 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31613 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-31614 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31614 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31614 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31767 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31767 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31767 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43052 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43052 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43052 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43234 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43234 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43249 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43249 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43249 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43325 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43333 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43333 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43338 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43341 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43359 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43359 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43359 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43361 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43361 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43361 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43362 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43362 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-43362 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43413 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43499 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43499 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45842 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45843 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45843 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45843 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45846 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45878 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45878 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46004 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46021 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46094 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46157 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46157 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46157 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46176 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 169 vulnerabilities and has 11 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() * CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). * CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). * CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). * CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). * CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). * CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). * CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). * CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). * CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). * CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). * CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). * CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). * CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). * CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). * CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). * CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: asihpi: Fix potential OOB array access at reading cache (stable- fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: sc6000: Keep the programmed board state in card-private data (git- fixes). * ALSA: sc6000: Use standard print API (stable-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: ua101: Reject too-short USB descriptors (git-fixes). * ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). * ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). * ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). * ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). * ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git- fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git- fixes). * Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git- fixes). * Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git- fixes). * Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). * Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). * Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). * Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git- fixes). * Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). * Bluetooth: bnep: reject short frames before parsing (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: Allow firmware re-download when version matches (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git- fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). * Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * HID: quirks: really enable the intended work around for appledisplay (git- fixes). * HID: uclogic: Fix regression of input name assignment (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * Improve compatibility with awk 2.4.0 (bsc#1266214). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). * Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). * Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git- fixes). * Input: xpad - fix out-of-bounds access for Share button (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git- fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * RDMA/efa: Check stored completion CTX command ID with received one (git- fixes) * RDMA/efa: Extend admin timeout error print (git-fixes) * RDMA/efa: Fix possible deadlock (git-fixes) * RDMA/efa: Improve admin completion context state machine (git-fixes) * RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). * wicked test: Added missing locking in backport (bsc#1267732). * USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git- fixes). * USB: serial: belkin_sa: validate interrupt status length (git-fixes). * USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git- fixes). * USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). * USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). * USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git- fixes). * USB: serial: safe_serial: fix memory corruption with small endpoint (git- fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) * auxdisplay: line-display: fix OOB read on zero-length message_store() (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). * batman-adv: clear current gateway during teardown (git-fixes). * batman-adv: dat: handle forward allocation error (git-fixes). * batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). * batman-adv: fix fragment reassembly length accounting (git-fixes). * batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). * batman-adv: frag: disallow unicast fragment in fragment (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * batman-adv: tt: fix negative last_changeset_len (git-fixes). * batman-adv: tt: fix negative tt_buff_len (git-fixes). * bcache: fix uninitialized closure object (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). * comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). * drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amd/display: Validate GPIO pin LUT table size before iterating (stable- fixes). * drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). * drm/amd/pm/si: Disregard vblank time when no displays are connected (git- fixes). * drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git- fixes). * drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). * drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: fix spelling typos (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git- fixes). * drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). * drm/bridge: megachips: remove bridge when irq request fails (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/hyperv: validate VMBus packet size in receive callback (git-fixes). * drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). * drm/i915: Fix potential UAF in TTM object purge (git-fixes). * drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable- fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dsi: do not dump registers past the mapped region (git-fixes). * drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). * efi: Allocate runtime workqueue before ACPI init (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). * firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). * hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). * hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes). * hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). * hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git- fixes). * hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git- fixes). * hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). * hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). * hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). * hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). * hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). * iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git- fixes). * iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). * iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). * iio: dac: ad5686: fix input raw value check (git-fixes). * iio: dac: max5821: fix return value check in powerdown sync (git-fixes). * iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). * iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). * iio: light: cm3323: fix reg_conf not being initialized correctly (git- fixes). * iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git- fixes). * iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). * iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). * kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: gro: do not merge zcopy skbs (git-fixes). * net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). * net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). * net: mana: Skip redundant detach on already-detached port (git-fixes). * net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). * net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). * net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). * net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). * net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). * phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). * platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). * platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). * r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). * rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538). * rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538). * rpm: Add BuildRequires for Rust enablement (bsc#1258538). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). * s390/entry: Scrub r12 register on kernel entry (bsc#1263068). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). * sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). * security/keys: fix missed RCU read section on lookup (stable-fixes). * serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git- fixes). * serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * smb: client: correctly handle ErrorContextData as a flexible array (git- fixes) * smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). * spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). * spi: st-ssc4: switch to use modern name (stable-fixes). * spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). * thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git- fixes). * tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). * tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). * usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). * usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). * usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). * usb: dwc2: Fix use after free in debug code (git-fixes). * usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). * usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). * usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). * usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). * usb: gadget: net2280: Fix double free in probe error path (git-fixes). * usb: usbtmc: check URB actual_length for interrupt-IN notifications (git- fixes). * usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git- fixes). * usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath10k: skip WMI and beacon transmission when device is wedged (git- fixes). * wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). * wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). * wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). * wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). * wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). * wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git- fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-498=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * kernel-devel-rt-6.4.0-48.1 * kernel-source-rt-6.4.0-48.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-rt-livepatch-6.4.0-48.1 * kernel-rt-debugsource-6.4.0-48.1 * kernel-rt-debuginfo-6.4.0-48.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-rt-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-38549.html * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23359.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-23444.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html * https://www.suse.com/security/cve/CVE-2026-31464.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31473.html * https://www.suse.com/security/cve/CVE-2026-31480.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31493.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-3150.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31516.html * https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31590.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31613.html * https://www.suse.com/security/cve/CVE-2026-31614.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31767.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43013.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43052.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43054.html * https://www.suse.com/security/cve/CVE-2026-43059.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-43234.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43249.html * https://www.suse.com/security/cve/CVE-2026-43252.html * https://www.suse.com/security/cve/CVE-2026-43261.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43296.html * https://www.suse.com/security/cve/CVE-2026-43325.html * https://www.suse.com/security/cve/CVE-2026-43333.html * https://www.suse.com/security/cve/CVE-2026-43338.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43341.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43359.html * https://www.suse.com/security/cve/CVE-2026-43360.html * https://www.suse.com/security/cve/CVE-2026-43361.html * https://www.suse.com/security/cve/CVE-2026-43362.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43413.html * https://www.suse.com/security/cve/CVE-2026-43414.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43483.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43499.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45843.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45878.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45910.html * https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46004.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46110.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46157.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46209.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1248235 * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260584 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1262634 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262656 * https://bugzilla.suse.com/show_bug.cgi?id=1262663 * https://bugzilla.suse.com/show_bug.cgi?id=1262668 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262755 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263152 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263769 * https://bugzilla.suse.com/show_bug.cgi?id=1263774 * https://bugzilla.suse.com/show_bug.cgi?id=1263790 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263945 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264011 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264063 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264093 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264124 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264184 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264300 * https://bugzilla.suse.com/show_bug.cgi?id=1264409 * https://bugzilla.suse.com/show_bug.cgi?id=1264430 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264476 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264551 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264669 * https://bugzilla.suse.com/show_bug.cgi?id=1264671 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264716 * https://bugzilla.suse.com/show_bug.cgi?id=1264719 * https://bugzilla.suse.com/show_bug.cgi?id=1264720 * https://bugzilla.suse.com/show_bug.cgi?id=1264722 * https://bugzilla.suse.com/show_bug.cgi?id=1264726 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1264805 * https://bugzilla.suse.com/show_bug.cgi?id=1264989 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265044 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265110 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265240 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1265960 * https://bugzilla.suse.com/show_bug.cgi?id=1266001 * https://bugzilla.suse.com/show_bug.cgi?id=1266009 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266238 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266307 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266395 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266414 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266759 * https://bugzilla.suse.com/show_bug.cgi?id=1266765 * https://bugzilla.suse.com/show_bug.cgi?id=1266767 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267222 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267663 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267726 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:36:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:36:53 -0000 Subject: SUSE-SU-2026:22432-1: important: Security update for helm Message-ID: <178306781368.117.8956301641959104988@2afce7b7fe24> # Security update for helm Announcement ID: SUSE-SU-2026:22432-1 Release Date: 2026-06-29T10:32:23Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 * update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-773=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-1.1 * helm-3.21.2-1.1 * SUSE Linux Micro 6.0 (noarch) * helm-bash-completion-3.21.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:36:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:36:59 -0000 Subject: SUSE-SU-2026:22431-1: important: Security update for dracut Message-ID: <178306781924.117.14631761113827891817@2afce7b7fe24> # Security update for dracut Announcement ID: SUSE-SU-2026:22431-1 Release Date: 2026-06-29T09:26:08Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.609.g1a2492e: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-772=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * dracut-fips-059+suse.609.g1a2492e-1.1 * dracut-debugsource-059+suse.609.g1a2492e-1.1 * dracut-059+suse.609.g1a2492e-1.1 * dracut-debuginfo-059+suse.609.g1a2492e-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:37:07 -0000 Subject: SUSE-SU-2026:22430-1: important: Security update for python-tornado6 Message-ID: <178306782778.117.401955000410782296@2afce7b7fe24> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22430-1 Release Date: 2026-06-26T09:07:54Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-770=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-tornado6-6.4-6.1 * python311-tornado6-debuginfo-6.4-6.1 * python-tornado6-debugsource-6.4-6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:37:14 -0000 Subject: SUSE-SU-2026:22429-1: important: Security update for sg3_utils Message-ID: <178306783400.117.783217827004864521@2afce7b7fe24> # Security update for sg3_utils Announcement ID: SUSE-SU-2026:22429-1 Release Date: 2026-06-26T09:07:54Z Rating: important References: * bsc#1267823 Affected Products: * SUSE Linux Micro 6.0 An update that has one fix can now be installed. ## Description: This update for sg3_utils fixes the following issue * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-771=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * sg3_utils-1.48~20221101+2.5a7572d6-1.1 * sg3_utils-debuginfo-1.48~20221101+2.5a7572d6-1.1 * libsgutils2-1_48-2-debuginfo-1.48~20221101+2.5a7572d6-1.1 * libsgutils2-1_48-2-1.48~20221101+2.5a7572d6-1.1 * sg3_utils-debugsource-1.48~20221101+2.5a7572d6-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267823 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:37:28 -0000 Subject: SUSE-SU-2026:22428-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306784854.117.18110248449503151312@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22428-1 Release Date: 2026-06-25T11:39:25Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-495=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-default-2-1.1 * kernel-livepatch-6_4_0-46-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:37:41 -0000 Subject: SUSE-SU-2026:22427-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306786156.117.13969939026017989856@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22427-1 Release Date: 2026-06-25T11:39:25Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-494=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-45-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-45-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_22-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:37:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:37:54 -0000 Subject: SUSE-SU-2026:22426-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306787467.117.18412893403441240942@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22426-1 Release Date: 2026-06-25T11:36:36Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-493=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_21-debugsource-2-1.1 * kernel-livepatch-6_4_0-44-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-44-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:38:13 -0000 Subject: SUSE-SU-2026:22425-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306789341.117.9461292298416787437@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22425-1 Release Date: 2026-06-25T11:36:36Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-492=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-43-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:38:21 -0000 Subject: SUSE-SU-2026:22424-1: important: Security update for containerd Message-ID: <178306790179.117.12368945744055880731@2afce7b7fe24> # Security update for containerd Announcement ID: SUSE-SU-2026:22424-1 Release Date: 2026-06-25T09:00:00Z Rating: important References: * bsc#1262948 * bsc#1265794 * bsc#1266640 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794). * CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-769=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * containerd-1.7.29-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262948 * https://bugzilla.suse.com/show_bug.cgi?id=1265794 * https://bugzilla.suse.com/show_bug.cgi?id=1266640 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:38:33 -0000 Subject: SUSE-SU-2026:22423-1: important: Security update for google-guest-agent Message-ID: <178306791363.117.575199960200526447@2afce7b7fe24> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:22423-1 Release Date: 2026-06-24T16:10:38Z Rating: important References: * bsc#1243254 * bsc#1243505 * bsc#1260264 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). Changes: * Update to version 20260529.00 * Dependency updates (#616) * from version 20260522.00 * Fix improper umask calculation on socket creation (#614) * from version 20260520.01 * Update OWNERS (#609) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Update to version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-768=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * google-guest-agent-20260529.00-1.1 * google-guest-agent-debuginfo-20260529.00-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:38:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:38:58 -0000 Subject: SUSE-SU-2026:22421-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306793808.117.6648381141305848663@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22421-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-491=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_17-debugsource-6-1.1 * kernel-livepatch-6_4_0-40-default-6-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:39:12 -0000 Subject: SUSE-SU-2026:22420-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306795233.117.15499271295804146353@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22420-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-490=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_16-debugsource-7-1.1 * kernel-livepatch-6_4_0-39-default-7-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:39:27 -0000 Subject: SUSE-SU-2026:22419-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306796783.117.15573908889773107538@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22419-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-489=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-8-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-8-1.2 * kernel-livepatch-6_4_0-38-default-debuginfo-8-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:39:43 -0000 Subject: SUSE-SU-2026:22418-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306798354.117.14552777457269247968@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22418-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-488=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-10-1.1 * kernel-livepatch-6_4_0-36-default-10-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:39:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:39:58 -0000 Subject: SUSE-SU-2026:22417-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306799831.117.269314435833024383@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22417-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-487=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-12-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:40:12 -0000 Subject: SUSE-SU-2026:22416-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306801256.117.6867195936859213442@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22416-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-486=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-12-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:40:27 -0000 Subject: SUSE-SU-2026:22415-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306802749.117.7334265736172513883@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22415-1 Release Date: 2026-06-24T09:59:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-485=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-13-1.1 * kernel-livepatch-6_4_0-32-default-13-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:40:40 -0000 Subject: SUSE-SU-2026:22414-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306804075.117.2247910767967776867@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22414-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-481=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-46-rt-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:40:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:40:56 -0000 Subject: SUSE-SU-2026:22413-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306805627.117.3674179387802553891@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22413-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-480=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-45-rt-debuginfo-2-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-2-1.2 * kernel-livepatch-6_4_0-45-rt-2-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:41:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:41:14 -0000 Subject: SUSE-SU-2026:22412-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306807430.117.6583749046373389288@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22412-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-479=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-43-rt-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-2-1.1 * kernel-livepatch-6_4_0-43-rt-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:41:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:41:32 -0000 Subject: SUSE-SU-2026:22411-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306809298.117.9692937045114342513@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22411-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-478=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-3-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-3-1.1 * kernel-livepatch-6_4_0-42-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:41:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:41:46 -0000 Subject: SUSE-SU-2026:22410-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306810601.117.16008260214654923768@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22410-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-477=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-5-1.1 * kernel-livepatch-6_4_0-41-rt-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:42:00 -0000 Subject: SUSE-SU-2026:22409-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306812080.117.402250447034684291@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22409-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-476=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-6-1.1 * kernel-livepatch-6_4_0-40-rt-6-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:42:15 -0000 Subject: SUSE-SU-2026:22408-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306813534.117.4055943590198516987@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22408-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-475=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-39-rt-debuginfo-7-1.1 * kernel-livepatch-6_4_0-39-rt-7-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:42:30 -0000 Subject: SUSE-SU-2026:22407-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306815042.117.18198046771628480367@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22407-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-474=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-38-rt-8-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:42:45 -0000 Subject: SUSE-SU-2026:22406-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306816523.117.18342767464833401947@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22406-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-473=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-37-rt-debuginfo-8-1.1 * kernel-livepatch-6_4_0-37-rt-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:42:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:42:59 -0000 Subject: SUSE-SU-2026:22405-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306817991.117.7441838940700777678@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22405-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-472=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-36-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-36-rt-12-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:43:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:43:15 -0000 Subject: SUSE-SU-2026:22404-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306819579.117.2541725764686903427@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22404-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-471=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-35-rt-13-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-13-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:43:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:43:31 -0000 Subject: SUSE-SU-2026:22403-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306821118.117.14031106435806585151@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22403-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-470=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-34-rt-17-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-17-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:43:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:43:54 -0000 Subject: SUSE-SU-2026:22402-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306823446.117.6131379488315521568@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22402-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-467=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-3-1.1 * kernel-livepatch-6_4_0-42-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:44:08 -0000 Subject: SUSE-SU-2026:22401-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306824829.117.16277005267113743764@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22401-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-466=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-5-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:44:23 -0000 Subject: SUSE-SU-2026:22400-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306826361.117.14641556940215421898@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22400-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-484=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-31-default-debuginfo-19-1.2 * kernel-livepatch-MICRO-6-0_Update_9-debugsource-19-1.2 * kernel-livepatch-6_4_0-31-default-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:44:38 -0000 Subject: SUSE-SU-2026:22399-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306827850.117.7687147491718911636@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22399-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-483=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-19-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-19-1.2 * kernel-livepatch-6_4_0-30-default-debuginfo-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:44:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:44:53 -0000 Subject: SUSE-SU-2026:22398-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306829324.117.12298592409400850179@2afce7b7fe24> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22398-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-29.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-482=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-29-default-20-1.2 * kernel-livepatch-MICRO-6-0_Update_7-debugsource-20-1.2 * kernel-livepatch-6_4_0-29-default-debuginfo-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:45:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:45:08 -0000 Subject: SUSE-SU-2026:22397-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306830804.117.14934036147403504614@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22397-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-33.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-469=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-33-rt-17-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-17-1.2 * kernel-livepatch-6_4_0-33-rt-debuginfo-17-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:45:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:45:22 -0000 Subject: SUSE-SU-2026:22396-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178306832269.117.17420231083295368010@2afce7b7fe24> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22396-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-468=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-31-rt-debuginfo-19-1.2 * kernel-livepatch-6_4_0-31-rt-19-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:45:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:45:28 -0000 Subject: SUSE-SU-2026:22395-1: moderate: Security update for crun Message-ID: <178306832868.117.2907356343471701356@2afce7b7fe24> # Security update for crun Announcement ID: SUSE-SU-2026:22395-1 Release Date: 2026-06-24T08:59:37Z Rating: moderate References: * bsc#1268302 Cross-References: * CVE-2026-47766 CVSS scores: * CVE-2026-47766 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for crun fixes the following issue * CVE-2026-47766: crun follows rootfs /dev symlink while creating default devices (bsc#1268302). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-766=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * crun-debuginfo-1.14-3.1 * crun-1.14-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47766.html * https://bugzilla.suse.com/show_bug.cgi?id=1268302 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:50:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:50:06 -0000 Subject: SUSE-SU-2026:22394-1: important: Security update for the Linux Kernel Message-ID: <178306860691.117.13341935125803215825@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22394-1 Release Date: 2026-06-30T17:26:45Z Rating: important References: * bsc#1248235 * bsc#1255416 * bsc#1256668 * bsc#1258538 * bsc#1260502 * bsc#1260584 * bsc#1261256 * bsc#1261619 * bsc#1261791 * bsc#1262085 * bsc#1262392 * bsc#1262606 * bsc#1262615 * bsc#1262617 * bsc#1262619 * bsc#1262620 * bsc#1262622 * bsc#1262624 * bsc#1262634 * bsc#1262649 * bsc#1262656 * bsc#1262663 * bsc#1262668 * bsc#1262674 * bsc#1262748 * bsc#1262755 * bsc#1262798 * bsc#1262993 * bsc#1263006 * bsc#1263068 * bsc#1263115 * bsc#1263123 * bsc#1263137 * bsc#1263143 * bsc#1263152 * bsc#1263178 * bsc#1263319 * bsc#1263562 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263724 * bsc#1263769 * bsc#1263774 * bsc#1263790 * bsc#1263879 * bsc#1263880 * bsc#1263883 * bsc#1263930 * bsc#1263932 * bsc#1263934 * bsc#1263945 * bsc#1263993 * bsc#1263996 * bsc#1264000 * bsc#1264011 * bsc#1264045 * bsc#1264063 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264093 * bsc#1264116 * bsc#1264124 * bsc#1264137 * bsc#1264145 * bsc#1264184 * bsc#1264239 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264263 * bsc#1264266 * bsc#1264300 * bsc#1264409 * bsc#1264430 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264476 * bsc#1264484 * bsc#1264549 * bsc#1264551 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264669 * bsc#1264671 * bsc#1264672 * bsc#1264716 * bsc#1264719 * bsc#1264720 * bsc#1264722 * bsc#1264726 * bsc#1264741 * bsc#1264763 * bsc#1264765 * bsc#1264805 * bsc#1264989 * bsc#1265020 * bsc#1265044 * bsc#1265073 * bsc#1265103 * bsc#1265110 * bsc#1265128 * bsc#1265143 * bsc#1265170 * bsc#1265240 * bsc#1265579 * bsc#1265628 * bsc#1265928 * bsc#1265960 * bsc#1266001 * bsc#1266009 * bsc#1266214 * bsc#1266238 * bsc#1266290 * bsc#1266307 * bsc#1266390 * bsc#1266394 * bsc#1266395 * bsc#1266397 * bsc#1266400 * bsc#1266402 * bsc#1266414 * bsc#1266452 * bsc#1266696 * bsc#1266697 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266711 * bsc#1266720 * bsc#1266759 * bsc#1266765 * bsc#1266767 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266878 * bsc#1266889 * bsc#1266895 * bsc#1266901 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266927 * bsc#1266933 * bsc#1266969 * bsc#1266972 * bsc#1267205 * bsc#1267208 * bsc#1267214 * bsc#1267218 * bsc#1267220 * bsc#1267222 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267531 * bsc#1267621 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267652 * bsc#1267654 * bsc#1267663 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267726 * bsc#1267732 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-38549 * CVE-2025-68324 * CVE-2025-68822 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23359 * CVE-2026-23438 * CVE-2026-23444 * CVE-2026-31396 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31464 * CVE-2026-31469 * CVE-2026-31473 * CVE-2026-31480 * CVE-2026-31492 * CVE-2026-31493 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-3150 * CVE-2026-31500 * CVE-2026-31516 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31555 * CVE-2026-31590 * CVE-2026-31592 * CVE-2026-31596 * CVE-2026-31613 * CVE-2026-31614 * CVE-2026-31629 * CVE-2026-31655 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31671 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31678 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31703 * CVE-2026-31752 * CVE-2026-31758 * CVE-2026-31759 * CVE-2026-31767 * CVE-2026-31771 * CVE-2026-43013 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43026 * CVE-2026-43028 * CVE-2026-43030 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43040 * CVE-2026-43049 * CVE-2026-43052 * CVE-2026-43053 * CVE-2026-43054 * CVE-2026-43059 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43109 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43206 * CVE-2026-43234 * CVE-2026-43239 * CVE-2026-43249 * CVE-2026-43252 * CVE-2026-43261 * CVE-2026-43284 * CVE-2026-43296 * CVE-2026-43325 * CVE-2026-43333 * CVE-2026-43338 * CVE-2026-43339 * CVE-2026-43341 * CVE-2026-43345 * CVE-2026-43359 * CVE-2026-43360 * CVE-2026-43361 * CVE-2026-43362 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43411 * CVE-2026-43413 * CVE-2026-43414 * CVE-2026-43455 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43483 * CVE-2026-43491 * CVE-2026-43499 * CVE-2026-43501 * CVE-2026-43503 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45842 * CVE-2026-45843 * CVE-2026-45846 * CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45878 * CVE-2026-45886 * CVE-2026-45894 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45970 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45984 * CVE-2026-46004 * CVE-2026-46005 * CVE-2026-46021 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46043 * CVE-2026-46079 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46101 * CVE-2026-46110 * CVE-2026-46111 * CVE-2026-46113 * CVE-2026-46114 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46157 * CVE-2026-46159 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46197 * CVE-2026-46209 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-38549 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-38549 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-38549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23359 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23359 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23359 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31464 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31464 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31464 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31473 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31480 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31480 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31493 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31493 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3150 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3150 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31516 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31613 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31613 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31613 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-31614 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31614 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31614 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31767 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31767 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31767 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43052 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43052 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43052 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43234 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43234 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43249 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43249 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43249 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43325 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43333 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43333 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43338 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43341 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43359 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43359 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43359 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43361 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43361 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43361 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43362 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43362 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-43362 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43413 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43499 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43499 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45842 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45843 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45843 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45843 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45846 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45878 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45878 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46004 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46021 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46094 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46157 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46157 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46157 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46176 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 169 vulnerabilities and has 11 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() * CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). * CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). * CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). * CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). * CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). * CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). * CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). * CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). * CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). * CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). * CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). * CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). * CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). * CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). * CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). * CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: asihpi: Fix potential OOB array access at reading cache (stable- fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: sc6000: Keep the programmed board state in card-private data (git- fixes). * ALSA: sc6000: Use standard print API (stable-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: ua101: Reject too-short USB descriptors (git-fixes). * ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). * ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). * ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). * ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). * ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git- fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git- fixes). * Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git- fixes). * Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git- fixes). * Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). * Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). * Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). * Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git- fixes). * Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). * Bluetooth: bnep: reject short frames before parsing (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: Allow firmware re-download when version matches (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git- fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). * Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * HID: quirks: really enable the intended work around for appledisplay (git- fixes). * HID: uclogic: Fix regression of input name assignment (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * Improve compatibility with awk 2.4.0 (bsc#1266214). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). * Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). * Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git- fixes). * Input: xpad - fix out-of-bounds access for Share button (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git- fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * RDMA/efa: Check stored completion CTX command ID with received one (git- fixes) * RDMA/efa: Extend admin timeout error print (git-fixes) * RDMA/efa: Fix possible deadlock (git-fixes) * RDMA/efa: Improve admin completion context state machine (git-fixes) * RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). * wicked test: Added missing locking in backport (bsc#1267732). * USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git- fixes). * USB: serial: belkin_sa: validate interrupt status length (git-fixes). * USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git- fixes). * USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). * USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). * USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git- fixes). * USB: serial: safe_serial: fix memory corruption with small endpoint (git- fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) * auxdisplay: line-display: fix OOB read on zero-length message_store() (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). * batman-adv: clear current gateway during teardown (git-fixes). * batman-adv: dat: handle forward allocation error (git-fixes). * batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). * batman-adv: fix fragment reassembly length accounting (git-fixes). * batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). * batman-adv: frag: disallow unicast fragment in fragment (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * batman-adv: tt: fix negative last_changeset_len (git-fixes). * batman-adv: tt: fix negative tt_buff_len (git-fixes). * bcache: fix uninitialized closure object (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). * comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). * drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amd/display: Validate GPIO pin LUT table size before iterating (stable- fixes). * drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). * drm/amd/pm/si: Disregard vblank time when no displays are connected (git- fixes). * drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git- fixes). * drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). * drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: fix spelling typos (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git- fixes). * drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). * drm/bridge: megachips: remove bridge when irq request fails (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/hyperv: validate VMBus packet size in receive callback (git-fixes). * drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). * drm/i915: Fix potential UAF in TTM object purge (git-fixes). * drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable- fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dsi: do not dump registers past the mapped region (git-fixes). * drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). * efi: Allocate runtime workqueue before ACPI init (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). * firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). * hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). * hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes). * hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). * hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git- fixes). * hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git- fixes). * hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). * hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). * hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). * hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). * hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). * iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git- fixes). * iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). * iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). * iio: dac: ad5686: fix input raw value check (git-fixes). * iio: dac: max5821: fix return value check in powerdown sync (git-fixes). * iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). * iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). * iio: light: cm3323: fix reg_conf not being initialized correctly (git- fixes). * iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git- fixes). * iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). * iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). * kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: gro: do not merge zcopy skbs (git-fixes). * net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). * net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). * net: mana: Skip redundant detach on already-detached port (git-fixes). * net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). * net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). * net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). * net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). * net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). * phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). * platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). * platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). * r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). * rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538). * rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538). * rpm: Add BuildRequires for Rust enablement (bsc#1258538). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). * s390/entry: Scrub r12 register on kernel entry (bsc#1263068). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). * sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). * security/keys: fix missed RCU read section on lookup (stable-fixes). * serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git- fixes). * serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * smb: client: correctly handle ErrorContextData as a flexible array (git- fixes) * smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). * spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). * spi: st-ssc4: switch to use modern name (stable-fixes). * spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). * thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git- fixes). * tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). * tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). * usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). * usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). * usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). * usb: dwc2: Fix use after free in debug code (git-fixes). * usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). * usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). * usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). * usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). * usb: gadget: net2280: Fix double free in probe error path (git-fixes). * usb: usbtmc: check URB actual_length for interrupt-IN notifications (git- fixes). * usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git- fixes). * usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath10k: skip WMI and beacon transmission when device is wedged (git- fixes). * wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). * wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). * wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). * wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). * wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). * wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git- fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-498=1 ## Package List: * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-48.1 * kernel-rt-devel-6.4.0-48.1 * kernel-rt-debugsource-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-rt-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-38549.html * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23359.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-23444.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html * https://www.suse.com/security/cve/CVE-2026-31464.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31473.html * https://www.suse.com/security/cve/CVE-2026-31480.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31493.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-3150.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31516.html * https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31590.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31613.html * https://www.suse.com/security/cve/CVE-2026-31614.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31767.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43013.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43052.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43054.html * https://www.suse.com/security/cve/CVE-2026-43059.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-43234.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43249.html * https://www.suse.com/security/cve/CVE-2026-43252.html * https://www.suse.com/security/cve/CVE-2026-43261.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43296.html * https://www.suse.com/security/cve/CVE-2026-43325.html * https://www.suse.com/security/cve/CVE-2026-43333.html * https://www.suse.com/security/cve/CVE-2026-43338.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43341.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43359.html * https://www.suse.com/security/cve/CVE-2026-43360.html * https://www.suse.com/security/cve/CVE-2026-43361.html * https://www.suse.com/security/cve/CVE-2026-43362.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43413.html * https://www.suse.com/security/cve/CVE-2026-43414.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43483.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43499.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45843.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45878.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45910.html * https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46004.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46110.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46157.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46209.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1248235 * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260584 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1262634 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262656 * https://bugzilla.suse.com/show_bug.cgi?id=1262663 * https://bugzilla.suse.com/show_bug.cgi?id=1262668 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262755 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263152 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263769 * https://bugzilla.suse.com/show_bug.cgi?id=1263774 * https://bugzilla.suse.com/show_bug.cgi?id=1263790 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263945 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264011 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264063 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264093 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264124 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264184 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264300 * https://bugzilla.suse.com/show_bug.cgi?id=1264409 * https://bugzilla.suse.com/show_bug.cgi?id=1264430 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264476 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264551 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264669 * https://bugzilla.suse.com/show_bug.cgi?id=1264671 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264716 * https://bugzilla.suse.com/show_bug.cgi?id=1264719 * https://bugzilla.suse.com/show_bug.cgi?id=1264720 * https://bugzilla.suse.com/show_bug.cgi?id=1264722 * https://bugzilla.suse.com/show_bug.cgi?id=1264726 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1264805 * https://bugzilla.suse.com/show_bug.cgi?id=1264989 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265044 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265110 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265240 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1265960 * https://bugzilla.suse.com/show_bug.cgi?id=1266001 * https://bugzilla.suse.com/show_bug.cgi?id=1266009 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266238 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266307 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266395 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266414 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266759 * https://bugzilla.suse.com/show_bug.cgi?id=1266765 * https://bugzilla.suse.com/show_bug.cgi?id=1266767 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267222 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267663 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267726 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:52:08 -0000 Subject: SUSE-SU-2026:22393-1: important: Security update for the Linux Kernel Message-ID: <178306872899.117.15741093265083467468@2afce7b7fe24> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22393-1 Release Date: 2026-06-30T23:09:03Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-496=1 ## Package List: * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-default-6.4.0-48.1 * kernel-64kb-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * kernel-syms-6.4.0-48.1 * kernel-default-devel-6.4.0-48.1 * kernel-default-debugsource-6.4.0-48.1 * kernel-obs-build-debugsource-6.4.0-48.1 * kernel-obs-build-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (aarch64) * kernel-64kb-debugsource-6.4.0-48.1 * kernel-64kb-devel-6.4.0-48.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-default-devel-debuginfo-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:52:36 -0000 Subject: SUSE-SU-2026:2733-1: important: Security update for buildah Message-ID: <178306875669.117.7958650385820071746@2afce7b7fe24> # Security update for buildah Announcement ID: SUSE-SU-2026:2733-1 Release Date: 2026-07-02T18:05:10Z Rating: important References: * bsc#1262953 * bsc#1266191 * bsc#1266648 * bsc#1267179 Cross-References: * CVE-2025-22869 * CVE-2025-27144 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-52881 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-52881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52881 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52881 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52881 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for buildah fixes the following issues * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267179). * CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262953). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266648). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266191). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266191). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266191). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266191). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266191). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2733=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2733=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2733=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2733=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2733=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2733=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2733=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2733=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * buildah-1.35.5-150500.3.62.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.62.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-27144.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-52881.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262953 * https://bugzilla.suse.com/show_bug.cgi?id=1266191 * https://bugzilla.suse.com/show_bug.cgi?id=1266648 * https://bugzilla.suse.com/show_bug.cgi?id=1267179 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:52:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:52:52 -0000 Subject: SUSE-SU-2026:2732-1: moderate: Security update for cups Message-ID: <178306877277.117.2789915034055236218@2afce7b7fe24> # Security update for cups Announcement ID: SUSE-SU-2026:2732-1 Release Date: 2026-07-02T17:41:51Z Rating: moderate References: * bsc#1261569 * bsc#1261570 * bsc#1261571 * bsc#1261572 * bsc#1261742 * bsc#1261743 Cross-References: * CVE-2026-27447 * CVE-2026-34978 * CVE-2026-34979 * CVE-2026-34980 * CVE-2026-39314 * CVE-2026-39316 CVSS scores: * CVE-2026-27447 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N * CVE-2026-27447 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N * CVE-2026-34978 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34978 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34979 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34979 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34980 ( SUSE ): 6.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L * CVE-2026-34980 ( NVD ): 6.1 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34980 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39314 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39314 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39314 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39314 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39316 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.2 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for cups fixes the following issues * CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). * CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). * CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). * CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). * CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). * CVE-2026-39316: dangling subscription pointer can lead to a denial of service (1261742). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2732=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2732=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2732=1 * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2732=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2732=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2732=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2732=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2732=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2732=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2732=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcupsimage2-debuginfo-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcupsppdc1-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcupsmime1-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-2.2.7-150000.3.93.1 * libcupsmime1-2.2.7-150000.3.93.1 * cups-client-debuginfo-2.2.7-150000.3.93.1 * libcupscgi1-debuginfo-2.2.7-150000.3.93.1 * libcupsppdc1-2.2.7-150000.3.93.1 * cups-devel-2.2.7-150000.3.93.1 * libcupsimage2-2.2.7-150000.3.93.1 * libcupscgi1-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * cups-client-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cups-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cups-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cups-debugsource-2.2.7-150000.3.93.1 * cups-debuginfo-2.2.7-150000.3.93.1 * cups-ddk-2.2.7-150000.3.93.1 * cups-ddk-debuginfo-2.2.7-150000.3.93.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * cups-debuginfo-2.2.7-150000.3.93.1 * cups-debugsource-2.2.7-150000.3.93.1 * libcups2-2.2.7-150000.3.93.1 * cups-config-2.2.7-150000.3.93.1 * libcups2-debuginfo-2.2.7-150000.3.93.1 * Desktop Applications Module 15-SP7 (x86_64) * libcups2-32bit-debuginfo-2.2.7-150000.3.93.1 * libcups2-32bit-2.2.7-150000.3.93.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27447.html * https://www.suse.com/security/cve/CVE-2026-34978.html * https://www.suse.com/security/cve/CVE-2026-34979.html * https://www.suse.com/security/cve/CVE-2026-34980.html * https://www.suse.com/security/cve/CVE-2026-39314.html * https://www.suse.com/security/cve/CVE-2026-39316.html * https://bugzilla.suse.com/show_bug.cgi?id=1261569 * https://bugzilla.suse.com/show_bug.cgi?id=1261570 * https://bugzilla.suse.com/show_bug.cgi?id=1261571 * https://bugzilla.suse.com/show_bug.cgi?id=1261572 * https://bugzilla.suse.com/show_bug.cgi?id=1261742 * https://bugzilla.suse.com/show_bug.cgi?id=1261743 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:53:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:53:00 -0000 Subject: SUSE-SU-2026:2731-1: moderate: Security update for editorconfig-core-c Message-ID: <178306878078.117.17304874395443392332@2afce7b7fe24> # Security update for editorconfig-core-c Announcement ID: SUSE-SU-2026:2731-1 Release Date: 2026-07-02T17:36:35Z Rating: moderate References: * bsc#1262131 Cross-References: * CVE-2026-40489 CVSS scores: * CVE-2026-40489 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40489 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for editorconfig-core-c fixes the following issue: * CVE-2026-40489: improper use of `strcpy` can lead to a stack buffer overflow (bsc#1262131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2731=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2731=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libeditorconfig-devel-0.12.6-150600.3.6.1 * editorconfig-core-c-debugsource-0.12.6-150600.3.6.1 * editorconfig-debuginfo-0.12.6-150600.3.6.1 * editorconfig-0.12.6-150600.3.6.1 * libeditorconfig0-debuginfo-0.12.6-150600.3.6.1 * libeditorconfig0-0.12.6-150600.3.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libeditorconfig-devel-64bit-0.12.6-150600.3.6.1 * libeditorconfig0-64bit-debuginfo-0.12.6-150600.3.6.1 * libeditorconfig0-64bit-0.12.6-150600.3.6.1 * openSUSE Leap 15.6 (x86_64) * libeditorconfig-devel-32bit-0.12.6-150600.3.6.1 * libeditorconfig0-32bit-debuginfo-0.12.6-150600.3.6.1 * libeditorconfig0-32bit-0.12.6-150600.3.6.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libeditorconfig0-debuginfo-0.12.6-150600.3.6.1 * editorconfig-core-c-debugsource-0.12.6-150600.3.6.1 * libeditorconfig0-0.12.6-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40489.html * https://bugzilla.suse.com/show_bug.cgi?id=1262131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:53:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:53:07 -0000 Subject: SUSE-SU-2026:2729-1: moderate: Security update for python-lxml Message-ID: <178306878735.117.10365982112142380737@2afce7b7fe24> # Security update for python-lxml Announcement ID: SUSE-SU-2026:2729-1 Release Date: 2026-07-02T17:31:24Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-lxml fixes the following issue * CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2729=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2729=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-lxml-devel-4.9.3-150400.8.11.1 * python-lxml-debugsource-4.9.3-150400.8.11.1 * python311-lxml-4.9.3-150400.8.11.1 * python311-lxml-debuginfo-4.9.3-150400.8.11.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-lxml-debugsource-4.9.3-150400.8.11.1 * python311-lxml-4.9.3-150400.8.11.1 * python311-lxml-debuginfo-4.9.3-150400.8.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 08:53:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 08:53:13 -0000 Subject: SUSE-SU-2026:2728-1: moderate: Security update for python-lxml Message-ID: <178306879340.117.15051813068495606989@2afce7b7fe24> # Security update for python-lxml Announcement ID: SUSE-SU-2026:2728-1 Release Date: 2026-07-02T17:30:54Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-lxml fixes the following issue * CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2728=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python-lxml-debugsource-3.6.1-8.8.1 * python-lxml-debuginfo-3.6.1-8.8.1 * python-lxml-3.6.1-8.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:30:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 12:30:15 -0000 Subject: SUSE-SU-2026:2739-1: important: Security update for fontforge Message-ID: <178308181582.202.8205704029251981805@dc2e3449a402> # Security update for fontforge Announcement ID: SUSE-SU-2026:2739-1 Release Date: 2026-07-03T08:05:31Z Rating: important References: * bsc#1256013 * bsc#1256025 * bsc#1256032 Cross-References: * CVE-2025-15269 * CVE-2025-15275 * CVE-2025-15279 CVSS scores: * CVE-2025-15269 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15269 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15275 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15275 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15279 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-15279 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for fontforge fixes the following issues * CVE-2025-15269: Remote Code Execution via Use-After-Free in SFD file parsing (bsc#1256032). * CVE-2025-15275: Arbitrary code execution via SFD file parsing buffer overflow (bsc#1256025). * CVE-2025-15279: Remote Code Execution via heap-based buffer overflow in BMP file parsing (bsc#1256013). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2739=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2739=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2739=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2739=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2739=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2739=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2739=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2739=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2739=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2739=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2739=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * fontforge-20200314-150200.3.18.1 * fontforge-debuginfo-20200314-150200.3.18.1 * fontforge-debugsource-20200314-150200.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15269.html * https://www.suse.com/security/cve/CVE-2025-15275.html * https://www.suse.com/security/cve/CVE-2025-15279.html * https://bugzilla.suse.com/show_bug.cgi?id=1256013 * https://bugzilla.suse.com/show_bug.cgi?id=1256025 * https://bugzilla.suse.com/show_bug.cgi?id=1256032 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 12:31:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 12:31:11 -0000 Subject: SUSE-SU-2026:2735-1: important: Security update for apache2 Message-ID: <178308187101.202.14174728094695420299@dc2e3449a402> # Security update for apache2 Announcement ID: SUSE-SU-2026:2735-1 Release Date: 2026-07-02T22:36:37Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2735=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2735=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2735=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * apache2-worker-2.4.66-150600.5.55.1 * apache2-event-debugsource-2.4.66-150600.5.55.1 * apache2-utils-debugsource-2.4.66-150600.5.55.1 * apache2-event-debuginfo-2.4.66-150600.5.55.1 * apache2-debuginfo-2.4.66-150600.5.55.1 * apache2-devel-2.4.66-150600.5.55.1 * apache2-utils-2.4.66-150600.5.55.1 * apache2-worker-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-2.4.66-150600.5.55.1 * apache2-event-2.4.66-150600.5.55.1 * apache2-prefork-debugsource-2.4.66-150600.5.55.1 * apache2-debugsource-2.4.66-150600.5.55.1 * apache2-worker-debuginfo-2.4.66-150600.5.55.1 * apache2-2.4.66-150600.5.55.1 * apache2-prefork-debuginfo-2.4.66-150600.5.55.1 * apache2-utils-debuginfo-2.4.66-150600.5.55.1 * openSUSE Leap 15.6 (noarch) * apache2-manual-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * apache2-manual-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * apache2-worker-2.4.66-150600.5.55.1 * apache2-utils-debugsource-2.4.66-150600.5.55.1 * apache2-debuginfo-2.4.66-150600.5.55.1 * apache2-devel-2.4.66-150600.5.55.1 * apache2-utils-2.4.66-150600.5.55.1 * apache2-worker-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-2.4.66-150600.5.55.1 * apache2-worker-debuginfo-2.4.66-150600.5.55.1 * apache2-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-debugsource-2.4.66-150600.5.55.1 * apache2-2.4.66-150600.5.55.1 * apache2-prefork-debuginfo-2.4.66-150600.5.55.1 * apache2-utils-debuginfo-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * apache2-worker-2.4.66-150600.5.55.1 * apache2-utils-debugsource-2.4.66-150600.5.55.1 * apache2-debuginfo-2.4.66-150600.5.55.1 * apache2-devel-2.4.66-150600.5.55.1 * apache2-utils-2.4.66-150600.5.55.1 * apache2-worker-debugsource-2.4.66-150600.5.55.1 * apache2-prefork-2.4.66-150600.5.55.1 * apache2-prefork-debugsource-2.4.66-150600.5.55.1 * apache2-debugsource-2.4.66-150600.5.55.1 * apache2-worker-debuginfo-2.4.66-150600.5.55.1 * apache2-2.4.66-150600.5.55.1 * apache2-prefork-debuginfo-2.4.66-150600.5.55.1 * apache2-utils-debuginfo-2.4.66-150600.5.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * apache2-manual-2.4.66-150600.5.55.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:30:25 -0000 Subject: SUSE-SU-2026:22491-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309622545.11236.9256041236307781022@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22491-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-481=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-46-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:30:39 -0000 Subject: SUSE-SU-2026:22490-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309623914.11236.10616877006054539692@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22490-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-480=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-2-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-2-1.2 * kernel-livepatch-6_4_0-45-rt-2-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:30:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:30:57 -0000 Subject: SUSE-SU-2026:22489-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309625702.11236.15623694494979286300@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22489-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-479=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-43-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-43-rt-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:31:15 -0000 Subject: SUSE-SU-2026:22488-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309627569.11236.11099685065349508764@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22488-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-478=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-42-rt-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-3-1.1 * kernel-livepatch-6_4_0-42-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:31:29 -0000 Subject: SUSE-SU-2026:22487-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309628926.11236.17027319068708748425@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22487-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-477=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-41-rt-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-5-1.1 * kernel-livepatch-6_4_0-41-rt-debuginfo-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:31:43 -0000 Subject: SUSE-SU-2026:22486-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309630362.11236.15445776878051227645@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22486-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-476=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-40-rt-6-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:31:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:31:59 -0000 Subject: SUSE-SU-2026:22485-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309631941.11236.13274060484653211755@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22485-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-475=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-39-rt-7-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-7-1.1 * kernel-livepatch-6_4_0-39-rt-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:32:13 -0000 Subject: SUSE-SU-2026:22484-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309633397.11236.5771611537004361492@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22484-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-474=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-8-1.1 * kernel-livepatch-6_4_0-38-rt-8-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:32:28 -0000 Subject: SUSE-SU-2026:22483-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309634877.11236.15308957082107106547@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22483-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-473=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-8-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-8-1.1 * kernel-livepatch-6_4_0-37-rt-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:32:43 -0000 Subject: SUSE-SU-2026:22482-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309636321.11236.11278918643996187577@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22482-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-472=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-12-1.1 * kernel-livepatch-6_4_0-36-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-36-rt-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:32:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:32:57 -0000 Subject: SUSE-SU-2026:22481-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309637773.11236.5899709053941547557@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22481-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-471=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-35-rt-debuginfo-13-1.1 * kernel-livepatch-6_4_0-35-rt-13-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:33:12 -0000 Subject: SUSE-SU-2026:22480-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309639206.11236.16777657850588232701@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22480-1 Release Date: 2026-06-24T09:59:05Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-470=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-34-rt-17-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-17-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:33:27 -0000 Subject: SUSE-SU-2026:22479-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309640726.11236.399089438000187610@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22479-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-33.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-469=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-33-rt-debuginfo-17-1.2 * kernel-livepatch-6_4_0-33-rt-17-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_9-debugsource-17-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:33:41 -0000 Subject: SUSE-SU-2026:22478-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309642176.11236.295904878640309085@4d746be3175e> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22478-1 Release Date: 2026-06-24T09:39:09Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-468=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-31-rt-debuginfo-19-1.2 * kernel-livepatch-MICRO-6-0-RT_Update_8-debugsource-19-1.2 * kernel-livepatch-6_4_0-31-rt-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:33:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:33:58 -0000 Subject: SUSE-SU-2026:22476-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309643829.11236.5447930963950742415@4d746be3175e> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22476-1 Release Date: 2026-06-25T11:39:19Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-495=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-2-1.1 * kernel-livepatch-6_4_0-46-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:34:11 -0000 Subject: SUSE-SU-2026:22475-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309645147.11236.14528896058299936248@4d746be3175e> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22475-1 Release Date: 2026-06-25T11:39:19Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-494=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_22-debugsource-2-1.1 * kernel-livepatch-6_4_0-45-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-45-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:34:30 -0000 Subject: SUSE-SU-2026:22474-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309647042.11236.4144954471351957963@4d746be3175e> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22474-1 Release Date: 2026-06-25T11:37:22Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-492=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-2-1.1 * kernel-livepatch-6_4_0-43-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:34:43 -0000 Subject: SUSE-SU-2026:22473-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309648334.11236.13076497392550621678@4d746be3175e> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22473-1 Release Date: 2026-06-25T11:36:14Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-493=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-44-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:34:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:34:58 -0000 Subject: SUSE-SU-2026:22472-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309649828.11236.3867169126956911215@4d746be3175e> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22472-1 Release Date: 2026-06-24T09:48:24Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-487=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-12-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:35:13 -0000 Subject: SUSE-SU-2026:22471-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309651395.11236.14376199284462295258@4d746be3175e> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22471-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-490=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-7-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-7-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:35:28 -0000 Subject: SUSE-SU-2026:22470-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309652828.11236.1542043748450834561@4d746be3175e> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22470-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-488=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-10-1.1 * kernel-livepatch-6_4_0-36-default-10-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:35:43 -0000 Subject: SUSE-SU-2026:22469-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309654382.11236.3835201288612780411@4d746be3175e> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22469-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-486=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-12-1.1 * kernel-livepatch-6_4_0-34-default-12-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:35:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:35:58 -0000 Subject: SUSE-SU-2026:22468-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309655877.11236.8646615153945501130@4d746be3175e> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22468-1 Release Date: 2026-06-24T09:46:55Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-485=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-13-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-13-1.1 * kernel-livepatch-6_4_0-32-default-debuginfo-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:36:12 -0000 Subject: SUSE-SU-2026:22467-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309657268.11236.1641811899053092266@4d746be3175e> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22467-1 Release Date: 2026-06-24T09:42:58Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-489=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-debuginfo-8-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-8-1.2 * kernel-livepatch-6_4_0-38-default-8-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:36:28 -0000 Subject: SUSE-SU-2026:22466-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309658838.11236.990943564689554053@4d746be3175e> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22466-1 Release Date: 2026-06-24T09:42:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-491=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_17-debugsource-6-1.1 * kernel-livepatch-6_4_0-40-default-6-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:36:42 -0000 Subject: SUSE-SU-2026:22465-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309660263.11236.13868760980273458004@4d746be3175e> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22465-1 Release Date: 2026-06-24T09:39:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-31.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-484=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_9-debugsource-19-1.2 * kernel-livepatch-6_4_0-31-default-debuginfo-19-1.2 * kernel-livepatch-6_4_0-31-default-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:36:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:36:56 -0000 Subject: SUSE-SU-2026:22464-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309661670.11236.4456859371350507384@4d746be3175e> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22464-1 Release Date: 2026-06-24T09:39:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-30.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-483=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-30-default-debuginfo-19-1.2 * kernel-livepatch-MICRO-6-0_Update_8-debugsource-19-1.2 * kernel-livepatch-6_4_0-30-default-19-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:37:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:37:10 -0000 Subject: SUSE-SU-2026:22463-1: important: Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309663068.11236.7454998150148372843@4d746be3175e> # Security update for the Linux Kernel (Live Patch 7 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22463-1 Release Date: 2026-06-24T09:39:06Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-29.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-482=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_7-debugsource-20-1.2 * kernel-livepatch-6_4_0-29-default-20-1.2 * kernel-livepatch-6_4_0-29-default-debuginfo-20-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:37:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:37:28 -0000 Subject: SUSE-SU-2026:22462-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309664869.11236.11003325659843263168@4d746be3175e> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22462-1 Release Date: 2026-06-24T09:32:59Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1264096 * bsc#1265224 * bsc#1265384 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2025-54518 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46300 * CVE-2026-46323 * CVE-2026-46333 CVSS scores: * CVE-2025-54518 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-54518 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-54518 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-54518 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46300 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46300 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46333 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues The following security issues were fixed: * CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264096). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46300: FragNesia attack: another xfrm/esp based local root exploit (bsc#1265224). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * CVE-2026-46333: ptrace: slightly saner 'get_dumpable()' logic (bsc#1265384). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-467=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_19-debugsource-3-1.1 * kernel-livepatch-6_4_0-42-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-42-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-54518.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46300.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://www.suse.com/security/cve/CVE-2026-46333.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1264096 * https://bugzilla.suse.com/show_bug.cgi?id=1265224 * https://bugzilla.suse.com/show_bug.cgi?id=1265384 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:37:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:37:51 -0000 Subject: SUSE-SU-2026:22461-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178309667128.11236.16773688878327221959@4d746be3175e> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:22461-1 Release Date: 2026-06-24T09:32:01Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-466=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-5-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:39:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:39:38 -0000 Subject: SUSE-SU-2026:22460-1: important: Security update for the Linux Kernel Message-ID: <178309677811.11236.9895589075614603717@4d746be3175e> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22460-1 Release Date: 2026-06-30T23:09:03Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-496=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-default-livepatch-6.4.0-48.1 * SUSE Linux Micro 6.1 (noarch) * kernel-macros-6.4.0-48.1 * kernel-devel-6.4.0-48.1 * kernel-source-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-48.1.21.25 * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-6.4.0-48.1 * kernel-default-devel-6.4.0-48.1 * kernel-default-debugsource-6.4.0-48.1 * SUSE Linux Micro 6.1 (ppc64le x86_64) * kernel-default-devel-debuginfo-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-48.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-kvmsmall-debuginfo-6.4.0-48.1 * kernel-kvmsmall-debugsource-6.4.0-48.1 * SUSE Linux Micro 6.1 (nosrc x86_64) * kernel-kvmsmall-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:39:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:39:45 -0000 Subject: SUSE-SU-2026:22459-1: moderate: Security update for pcr-oracle Message-ID: <178309678506.11236.12978405677182084215@4d746be3175e> # Security update for pcr-oracle Announcement ID: SUSE-SU-2026:22459-1 Release Date: 2026-06-30T23:03:29Z Rating: moderate References: * bsc#1265042 * bsc#1265871 Affected Products: * SUSE Linux Micro 6.1 An update that has two fixes can now be installed. ## Description: This update for pcr-oracle fixes the following issues Update to 0.6.3: Security issue: * integer underflow vulnerability in `parse_sbatlevel_section()` (bsc#1265042). Non security issue: * Lockout Authorization error for libvirt-emulated TPM (bsc#1265871). Changes for pcr-oracle: * Relax TPM self-test attribute checks (bsc#1265871) * Update the SBAT offset boundary check (bsc#1265042) * Advance the comparison event pointer after comparison * Partially support shim extra files * Locate shim extra files * Synthesize shim extra events * Fix various issues from review by Claude Code and introduce adversarial testing ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-606=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * pcr-oracle-debugsource-0.6.3-slfo.1.1_1.1 * pcr-oracle-0.6.3-slfo.1.1_1.1 * pcr-oracle-debuginfo-0.6.3-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1265042 * https://bugzilla.suse.com/show_bug.cgi?id=1265871 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:03 -0000 Subject: SUSE-SU-2026:22458-1: important: Security update for the Linux Kernel Message-ID: <178309704376.11236.8876750275663351962@4d746be3175e> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22458-1 Release Date: 2026-06-30T17:41:36Z Rating: important References: * bsc#1248235 * bsc#1255416 * bsc#1256668 * bsc#1258538 * bsc#1260502 * bsc#1260584 * bsc#1261256 * bsc#1261619 * bsc#1261791 * bsc#1262085 * bsc#1262392 * bsc#1262606 * bsc#1262615 * bsc#1262617 * bsc#1262619 * bsc#1262620 * bsc#1262622 * bsc#1262624 * bsc#1262634 * bsc#1262649 * bsc#1262656 * bsc#1262663 * bsc#1262668 * bsc#1262674 * bsc#1262748 * bsc#1262755 * bsc#1262798 * bsc#1262993 * bsc#1263006 * bsc#1263068 * bsc#1263115 * bsc#1263123 * bsc#1263137 * bsc#1263143 * bsc#1263152 * bsc#1263178 * bsc#1263319 * bsc#1263562 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263724 * bsc#1263769 * bsc#1263774 * bsc#1263790 * bsc#1263879 * bsc#1263880 * bsc#1263883 * bsc#1263930 * bsc#1263932 * bsc#1263934 * bsc#1263945 * bsc#1263993 * bsc#1263996 * bsc#1264000 * bsc#1264011 * bsc#1264045 * bsc#1264063 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264093 * bsc#1264116 * bsc#1264124 * bsc#1264137 * bsc#1264145 * bsc#1264184 * bsc#1264239 * bsc#1264243 * bsc#1264245 * bsc#1264255 * bsc#1264263 * bsc#1264266 * bsc#1264300 * bsc#1264409 * bsc#1264430 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264476 * bsc#1264484 * bsc#1264549 * bsc#1264551 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264669 * bsc#1264671 * bsc#1264672 * bsc#1264716 * bsc#1264719 * bsc#1264720 * bsc#1264722 * bsc#1264726 * bsc#1264741 * bsc#1264763 * bsc#1264765 * bsc#1264805 * bsc#1264989 * bsc#1265020 * bsc#1265044 * bsc#1265073 * bsc#1265103 * bsc#1265110 * bsc#1265128 * bsc#1265143 * bsc#1265170 * bsc#1265240 * bsc#1265579 * bsc#1265628 * bsc#1265928 * bsc#1265960 * bsc#1266001 * bsc#1266009 * bsc#1266214 * bsc#1266238 * bsc#1266290 * bsc#1266307 * bsc#1266390 * bsc#1266394 * bsc#1266395 * bsc#1266397 * bsc#1266400 * bsc#1266402 * bsc#1266414 * bsc#1266452 * bsc#1266696 * bsc#1266697 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266711 * bsc#1266720 * bsc#1266759 * bsc#1266765 * bsc#1266767 * bsc#1266810 * bsc#1266816 * bsc#1266826 * bsc#1266827 * bsc#1266878 * bsc#1266889 * bsc#1266895 * bsc#1266901 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266927 * bsc#1266933 * bsc#1266969 * bsc#1266972 * bsc#1267205 * bsc#1267208 * bsc#1267214 * bsc#1267218 * bsc#1267220 * bsc#1267222 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267531 * bsc#1267621 * bsc#1267624 * bsc#1267626 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267652 * bsc#1267654 * bsc#1267663 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267726 * bsc#1267732 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-38549 * CVE-2025-68324 * CVE-2025-68822 * CVE-2026-23303 * CVE-2026-23327 * CVE-2026-23359 * CVE-2026-23438 * CVE-2026-23444 * CVE-2026-31396 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31446 * CVE-2026-31448 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31454 * CVE-2026-31455 * CVE-2026-31464 * CVE-2026-31469 * CVE-2026-31473 * CVE-2026-31480 * CVE-2026-31492 * CVE-2026-31493 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-3150 * CVE-2026-31500 * CVE-2026-31516 * CVE-2026-31518 * CVE-2026-31546 * CVE-2026-31555 * CVE-2026-31590 * CVE-2026-31592 * CVE-2026-31596 * CVE-2026-31613 * CVE-2026-31614 * CVE-2026-31629 * CVE-2026-31655 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31671 * CVE-2026-31673 * CVE-2026-31674 * CVE-2026-31678 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31703 * CVE-2026-31752 * CVE-2026-31758 * CVE-2026-31759 * CVE-2026-31767 * CVE-2026-31771 * CVE-2026-43013 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43026 * CVE-2026-43028 * CVE-2026-43030 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43040 * CVE-2026-43049 * CVE-2026-43052 * CVE-2026-43053 * CVE-2026-43054 * CVE-2026-43059 * CVE-2026-43065 * CVE-2026-43066 * CVE-2026-43068 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43109 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43206 * CVE-2026-43234 * CVE-2026-43239 * CVE-2026-43249 * CVE-2026-43252 * CVE-2026-43261 * CVE-2026-43284 * CVE-2026-43296 * CVE-2026-43325 * CVE-2026-43333 * CVE-2026-43338 * CVE-2026-43339 * CVE-2026-43341 * CVE-2026-43345 * CVE-2026-43359 * CVE-2026-43360 * CVE-2026-43361 * CVE-2026-43362 * CVE-2026-43405 * CVE-2026-43406 * CVE-2026-43407 * CVE-2026-43411 * CVE-2026-43413 * CVE-2026-43414 * CVE-2026-43455 * CVE-2026-43469 * CVE-2026-43470 * CVE-2026-43483 * CVE-2026-43491 * CVE-2026-43499 * CVE-2026-43501 * CVE-2026-43503 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45842 * CVE-2026-45843 * CVE-2026-45846 * CVE-2026-45852 * CVE-2026-45856 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45878 * CVE-2026-45886 * CVE-2026-45894 * CVE-2026-45910 * CVE-2026-45932 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45970 * CVE-2026-45974 * CVE-2026-45983 * CVE-2026-45984 * CVE-2026-46004 * CVE-2026-46005 * CVE-2026-46021 * CVE-2026-46024 * CVE-2026-46037 * CVE-2026-46043 * CVE-2026-46079 * CVE-2026-46083 * CVE-2026-46090 * CVE-2026-46094 * CVE-2026-46101 * CVE-2026-46110 * CVE-2026-46111 * CVE-2026-46113 * CVE-2026-46114 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46157 * CVE-2026-46159 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46176 * CVE-2026-46181 * CVE-2026-46197 * CVE-2026-46209 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-38549 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-38549 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-38549 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23303 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23327 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-23359 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23359 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23359 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23438 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23438 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23438 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23444 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23444 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31396 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31396 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-31396 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31446 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-31448 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31448 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31454 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31455 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31455 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31464 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31464 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31464 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31473 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31473 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31480 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31480 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31480 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31493 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31493 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3150 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3150 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-3150 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31516 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31516 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31518 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31518 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31518 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31546 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31590 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31596 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31596 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31613 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31613 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31613 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-31614 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31614 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31614 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31655 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31655 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31655 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31671 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-31671 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-31671 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31673 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-31673 ( SUSE ): 4.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-31673 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31678 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31678 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31678 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31703 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31703 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31703 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31767 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31767 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31767 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43013 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43013 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43026 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43030 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43030 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43052 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43052 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43052 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43054 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43059 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43065 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-43065 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-43065 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43066 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43066 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43068 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43068 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43068 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43234 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43234 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43249 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43249 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43249 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43252 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43325 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43325 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43333 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43333 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43333 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43338 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43341 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43359 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43359 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43359 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43360 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43361 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43361 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43361 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43362 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-43362 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-43362 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43407 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43411 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43411 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43413 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43413 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43455 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43499 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43499 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43499 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45842 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45842 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45843 ( SUSE ): 7.0 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45843 ( SUSE ): 6.3 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45843 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-45846 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45846 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45846 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45852 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45852 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45852 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45856 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45856 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45856 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45878 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45878 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45886 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45886 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45910 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45910 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45932 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45932 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45984 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45984 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45984 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46004 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46021 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46021 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46024 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46024 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46043 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46079 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46094 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46094 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46094 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46110 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46111 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46111 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46114 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46114 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-46114 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46157 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46157 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46157 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46159 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46159 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46176 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46181 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46181 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 169 vulnerabilities and has 11 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-38549: efivarfs: Fix memory leak of efivarfs_fs_info in fs_context error paths (bsc#1248235). * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-23303: smb: client: Don't log plaintext credentials in cifs_set_cifscreds (bsc#1260502). * CVE-2026-23327: cxl/mbox: validate payload size before accessing contents in cxl_payload_from_user_allowed() * CVE-2026-23359: bpf: Fix stack-out-of-bounds write in devmap (bsc#1260584). * CVE-2026-23438: net: mvpp2: guard flow control update with global_tx_fc in buffer switching (bsc#1261619). * CVE-2026-23444: wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure (bsc#1266307). * CVE-2026-31396: net: macb: fix use-after-free access to PTP clock (bsc#1261791). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31446: ext4: fix use-after-free in update_super_work when racing with umount (bsc#1262619). * CVE-2026-31448: ext4: avoid infinite loops caused by residual data (bsc#1262622). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31454: xfs: save ailp before dropping the AIL lock in push callbacks (bsc#1262624). * CVE-2026-31455: xfs: stop reclaim before pushing AIL during unmount (bsc#1262615). * CVE-2026-31464: scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done() (bsc#1262656). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31473: media: mc, v4l2: serialize REINIT and REQBUFS with req_queue_mutex (bsc#1262663). * CVE-2026-31480: tracing: Fix potential deadlock in cpu hotplug with osnoise (bsc#1262634). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31493: RDMA/efa: Fix use of completion ctx after free (bsc#1262668). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31516: xfrm: prevent policy_hthresh.work from racing with netns teardown (bsc#1262755). * CVE-2026-31518: esp: fix skb leak with espintcp and async crypto (bsc#1262606). * CVE-2026-31546: net: bonding: fix NULL deref in bond_debug_rlb_hash_show (bsc#1263006). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31590: KVM: SEV: Drop WARN on large size for KVM_MEMORY_ENCRYPT_REG_REGION (bsc#1263152). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31596: ocfs2: handle invalid dinode in ocfs2_group_extend (bsc#1263319). * CVE-2026-31613: smb: client: fix OOB reads parsing symlink error response (bsc#1263769). * CVE-2026-31614: smb: client: fix off-by-8 bounds check in check_wsl_eas() (bsc#1263774). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263790). * CVE-2026-31655: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled (bsc#1263724). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31671: xfrm_user: fix info leak in build_report() (bsc#1263115). * CVE-2026-31673: af_unix: read UNIX_DIAG_VFS data under unix_state_lock (bsc#1263143). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31678: openvswitch: defer tunnel netdev_put to RCU release (bsc#1263562). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31703: writeback: Fix use after free in inode_switch_wbs_work_fn() (bsc#1263883). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264093). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31767: drm/i915/dsi: Don't do DSC horizontal timing adjustments in command mode (bsc#1264124). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43013: net/mlx5: lag: Check for LAG device before creating debugfs (bsc#1264011). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43026: netfilter: ctnetlink: zero expect NAT fields when CTA_EXPECT_NAT absent (bsc#1263932). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43030: bpf: Fix regsafe() for pointers to packet (bsc#1264000). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43040: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info- * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43052: wifi: mac80211: check tdls flag in ieee80211_tdls_oper (bsc#1263945). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43054: scsi: target: tcm_loop: Drain commands in target_reset handler (bsc#1264063). * CVE-2026-43059: Bluetooth: MGMT: fix crash in set_mesh_sync and set_mesh_complete (bsc#1264184). * CVE-2026-43065: ext4: always drain queued discard work in ext4_mb_release() (bsc#1264243). * CVE-2026-43066: ext4: fix iloc.bh leak in ext4_fc_replay_inode() error paths (bsc#1264245). * CVE-2026-43068: ext4: avoid allocate block from corrupted group in ext4_mb_find_by_goal() (bsc#1264255). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1264551). * CVE-2026-43234: team: avoid NETDEV_CHANGEMTU event when unregistering slave (bsc#1264409). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43249: 9p/xen: protect xen_9pfs_front_free against concurrent calls (bsc#1264476). * CVE-2026-43252: mptcp: pm: in-kernel: always set ID as avail when rm endp (bsc#1264300). * CVE-2026-43261: arm64: Add support for TSV110 Spectre-BHB mitigation (bsc#1264430). * CVE-2026-43296: octeontx2-af: Workaround SQM/PSE stalls by disabling sticky (bsc#1264805). * CVE-2026-43325: wifi: iwlwifi: mvm: don't send a 6E related command when not supported (bsc#1265110). * CVE-2026-43333: bpf: reject direct access to nullable PTR_TO_BUF pointers (bsc#1264726). * CVE-2026-43338: btrfs: reserve enough transaction items for qgroup ioctls (bsc#1264716). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43341: net/ipv6: ioam6: prevent schema length wraparound in trace fill (bsc#1265044). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43359: btrfs: fix transaction abort on set received ioctl due to item overflow (bsc#1264719). * CVE-2026-43360: btrfs: fix transaction abort on file creation due to name hash collision (bsc#1264720). * CVE-2026-43361: btrfs: fix transaction abort when snapshotting received subvolumes (bsc#1264722). * CVE-2026-43362: smb: client: fix in-place encryption corruption in SMB2_write() (bsc#1264989). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43406: libceph: prevent potential out-of-bounds reads in process_message_header() (bsc#1265073). * CVE-2026-43407: libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply() (bsc#1265020). * CVE-2026-43411: tipc: fix divide-by-zero in tipc_sk_filter_connect() (bsc#1264672). * CVE-2026-43413: scsi: hisi_sas: Fix NULL pointer exception during user_scan() (bsc#1264671). * CVE-2026-43414: scsi: qla2xxx: Completely fix fcport double free (bsc#1264669). * CVE-2026-43455: net: mctp: Ensure keys maintain only one ref to corresponding dev (bsc#1264765). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43470: nfs: return EISDIR on nfs3_proc_create if d_alias is a dir (bsc#1265128). * CVE-2026-43483: KVM: SVM: Set/clear CR8 write interception when AVIC is (de)activated (bsc#1265240). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43499: rtmutex: Use waiter::task instead of current in remove_waiter() (bsc#1266001). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266009). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45842: slip: reject VJ receive packets on instances with no rstate array (bsc#1266400). * CVE-2026-45843: slip: bound decode() reads against the compressed packet length (bsc#1266395). * CVE-2026-45846: bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() (bsc#1266394). * CVE-2026-45852: RDMA/rxe: Fix double free in rxe_srq_from_init (bsc#1266711). * CVE-2026-45856: RDMA/uverbs: Validate wqe_size before using it in ib_uverbs_post_send (bsc#1266720). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45878: drm/amdkfd: Fix watch_id bounds checking in debug address watch v2 (bsc#1266767). * CVE-2026-45886: bpf: Fix bpf_xdp_store_bytes proto for read-only arg (bsc#1266810). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45910: RDMA/rxe: Fix race condition in QP timer handlers (bsc#1266889). * CVE-2026-45932: bpf: Fix tcx/netkit detach permissions when prog fd isn't given (bsc#1266827). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45983: nfsd: never defer requests during idmap lookup (bsc#1266697). * CVE-2026-45984: gfs2: Move the inode glock locking to gfs2_file_buffered_write (bsc#1267214). * CVE-2026-46004: ALSA: caiaq: Handle probe errors properly (bsc#1267222). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46021: thermal: core: Fix thermal zone governor cleanup issues (bsc#1267220). * CVE-2026-46024: libceph: Prevent potential null-ptr-deref in ceph_handle_auth_reply() (bsc#1267218). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46043: RDMA/rxe: Validate pad and ICRC before payload_size() in rxe_rcv (bsc#1266901). * CVE-2026-46079: rbd: fix null-ptr-deref when device_add_disk() fails (bsc#1266452). * CVE-2026-46083: spi: fix resource leaks on device setup failure (bsc#1266696). * CVE-2026-46090: ALSA: aloop: Use guard() for spin locks (bsc#1267531). * CVE-2026-46094: ext4: fix bounds check in check_xattrs() to prevent out-of- bounds access (bsc#1266927). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46110: net: stmmac: rename STMMAC_GET_ENTRY() -> STMMAC_NEXT_ENTRY() (bsc#1266759). * CVE-2026-46111: Bluetooth: hci_conn: fix potential UAF in create_big_sync (bsc#1267626). * CVE-2026-46113: KVM: x86/mmu: Add helper to convert SPTE value to its shadow page (bsc#1266969). * CVE-2026-46114: RDMA/rxe: Reject non-8-byte ATOMIC_WRITE payloads (bsc#1266972). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46157: ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger (bsc#1267726). * CVE-2026-46159: btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-leak (bsc#1267652). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46176: RDMA/mlx5: Fix error path fall-through in mlx5_ib_dev_res_srq_init() (bsc#1266816). * CVE-2026-46181: RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() (bsc#1266826). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46209: drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with_funcs() (bsc#1267663). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: asihpi: Fix potential OOB array access at reading cache (stable- fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/conexant: Renaming the codec with device ID 0x1f86 and 0x1f87 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: sc6000: Keep the programmed board state in card-private data (git- fixes). * ALSA: sc6000: Use standard print API (stable-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: ua101: Reject too-short USB descriptors (git-fixes). * ALSA: usb-audio: Bound MIDI 2.0 endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Bound MIDI endpoint descriptor scans (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: Intel: hda-dai: add support for dspless mode beyond HDAudio (stable-fixes). * ASoC: SOF: Intel: hda-dai: remove dspless special case (stable-fixes). * ASoC: SOF: Intel: hda: Fix NULL pointer dereference (stable-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: codecs: simple-mux: Fix enum control bounds check (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix flushing of IRQ work in cs35l56_sdw_remove() (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6asm-dai: close stream only when running (git-fixes). * ASoC: qcom: q6asm-dai: do not set stream state in event and trigger callbacks (git-fixes). * ASoC: qcom: q6asm-dai: fix error handling in prepare and set_params (git- fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() (git- fixes). * Bluetooth: HIDP: fix missing length checks in hidp_input_report() (git- fixes). * Bluetooth: ISO: drop ISO_END frames received without prior ISO_START (git- fixes). * Bluetooth: ISO: fix UAF in iso_recv_frame (git-fixes). * Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock (git-fixes). * Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp (git-fixes). * Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn (git- fixes). * Bluetooth: L2CAP: use chan timer to close channels in cleanup_listen() (git- fixes). * Bluetooth: MGMT: Fix backward compatibility with userspace (git-fixes). * Bluetooth: MGMT: validate Add Extended Advertising Data length (git-fixes). * Bluetooth: MGMT: validate advertising TLV before type checks (git-fixes). * Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind() (git-fixes). * Bluetooth: RFCOMM: validate skb length in MCC handlers (git-fixes). * Bluetooth: bnep: Fix UAF read of dev->name (git-fixes). * Bluetooth: bnep: reject short frames before parsing (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: Allow firmware re-download when version matches (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del() (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close (git- fixes). * Bluetooth: hci_sync: reject oversized Broadcast Announcement prepend (git- fixes). * Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (git-fixes). * Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success (git- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * HID: quirks: really enable the intended work around for appledisplay (git- fixes). * HID: uclogic: Fix regression of input name assignment (git-fixes). * HID: wacom: Fix OOB write in wacom_hid_set_device_mode() (git-fixes). * Improve compatibility with awk 2.4.0 (bsc#1266214). * Input: atkbd - skip deactivate for HONOR BCC-N's internal keyboard (git- fixes). * Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem (git-fixes). * Input: ims-pcu - fix usb_free_coherent() size in ims_pcu_buffers_free() (git-fixes). * Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size (git- fixes). * Input: xpad - fix out-of-bounds access for Share button (git-fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Initialize AVIC VMCB fields if AVIC is enabled with in-kernel APIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: X86: Fix array_index_nospec protection in __pv_send_ipi (git-fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: nSVM: Use vcpu->arch.cr2 when updating vmcb12 on nested #VMEXIT (git- fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86: Fix Xen hypercall tracepoint argument assignment (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * RDMA/efa: Check stored completion CTX command ID with received one (git- fixes) * RDMA/efa: Extend admin timeout error print (git-fixes) * RDMA/efa: Fix possible deadlock (git-fixes) * RDMA/efa: Improve admin completion context state machine (git-fixes) * RDMA/mana_ib: Report max_msg_sz in mana_ib_query_port (git-fixes). * wicked test: Added missing locking in backport (bsc#1267732). * USB: cdc-acm: Fix bit overlap and move quirk definitions to header (git- fixes). * USB: serial: belkin_sa: validate interrupt status length (git-fixes). * USB: serial: cypress_m8: validate interrupt packet headers (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: keyspan: fix missing indat transfer sanity check (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: mct_u232: fix missing interrupt-in transfer sanity check (git- fixes). * USB: serial: mxuport: fix memory corruption with small endpoint (git-fixes). * USB: serial: omninet: fix memory corruption with small endpoint (git-fixes). * USB: serial: option: add missing RSVD(5) flag for Rolling RW135R-GL (git- fixes). * USB: serial: safe_serial: fix memory corruption with small endpoint (git- fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * arm64: tlb: Allow XZR argument to TLBI ops (git-fixes) * arm64: tlb: Optimize ARM64_WORKAROUND_REPEAT_TLBI (git-fixes) * auxdisplay: line-display: fix OOB read on zero-length message_store() (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: bla: fix report_work leak on backbone_gw purge (git-fixes). * batman-adv: clear current gateway during teardown (git-fixes). * batman-adv: dat: handle forward allocation error (git-fixes). * batman-adv: fix batadv_skb_is_frag() kernel-doc (git-fixes). * batman-adv: fix fragment reassembly length accounting (git-fixes). * batman-adv: fix tp_meter counter underflow during shutdown (git-fixes). * batman-adv: frag: disallow unicast fragment in fragment (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid use of uninit sender vars (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * batman-adv: tt: fix negative last_changeset_len (git-fixes). * batman-adv: tt: fix negative tt_buff_len (git-fixes). * bcache: fix uninitialized closure object (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * comedi: comedi_test: Fix limiting of convert_arg in waveform_ai_cmdtest() (git-fixes). * comedi: comedi_test: fix check for valid scan_begin_src in waveform_ai_cmdtest() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * device property: set fwnode->secondary to NULL in fwnode_init() (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drivers/base/memory: fix memory block reference leak in poison accounting (git-fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp HDMI HDCP2 rx_id_list read to buffer size (git- fixes). * drm/amd/display: Fix NULL deref and buffer over-read in SDP debugfs (git- fixes). * drm/amd/display: Fix integer overflow in bios_get_image() (stable-fixes). * drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info() (git-fixes). * drm/amd/display: Use krealloc_array() in dal_vector_reserve() (git-fixes). * drm/amd/display: Validate GPIO pin LUT table size before iterating (stable- fixes). * drm/amd/display: Validate payload length and link_index in dc_process_dmub_aux_transfer_async (stable-fixes). * drm/amd/pm/si: Disregard vblank time when no displays are connected (git- fixes). * drm/amdgpu/uvd3.1: Do not validate the firmware when already validated (git- fixes). * drm/amdgpu/vce2: Fix VCE 2 firmware size and offsets (git-fixes). * drm/amdgpu/vce3: Fix VCE 3 firmware size and offsets (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: fix spelling typos (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/amdkfd: fix NULL dereference in get_queue_ids() (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/bridge: chipone-icn6211: use devm_drm_bridge_add in i2c probe (git- fixes). * drm/bridge: it66121: acquire reset GPIO in probe (git-fixes). * drm/bridge: megachips: remove bridge when irq request fails (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/hyperv: validate VMBus packet size in receive callback (git-fixes). * drm/hyperv: validate resolution_count and fix WIN8 fallback (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915: Extract intel_dbuf_mdclk_cdclk_ratio_update() (stable-fixes). * drm/i915: Fix potential UAF in TTM object purge (git-fixes). * drm/i915: Loop over all active pipes in intel_mbus_dbox_update (stable- fixes). * drm/imx: Fix three kernel-doc warnings in dcss-scaler.c (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dsi: do not dump registers past the mapped region (git-fixes). * drm/msm/snapshot: fix dumping of the unaligned regions (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon/evergreen_cs: Add missing NULL prefix check in surface check (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: use uninterruptible resv lock for plane updates (git-fixes). * efi: Allocate runtime workqueue before ACPI init (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_ffa: Check for NULL FF-A ID table while driver registration (git-fixes). * firmware: arm_ffa: Skip free_pages on RX buffer alloc failure (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer (git-fixes). * hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR (git-fixes). * hwmon: (pmbus/adm1266) do not clobber GPIO bits before PDIO read in get_multiple (git-fixes). * hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer (git-fixes). * hwmon: (pmbus/adm1266) include adapter number in GPIO line label (git- fixes). * hwmon: (pmbus/adm1266) register the gpio_chip after pmbus_do_probe() (git- fixes). * hwmon: (pmbus/adm1266) register the nvmem device after pmbus_do_probe() (git-fixes). * hwmon: (pmbus/adm1266) reject implausible blackbox record_count (git-fixes). * hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors (git-fixes). * hwmon: (pmbus/adm1266) seed timestamp from the real-time clock (git-fixes). * hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * iio: adc: viperboard: Fix error handling in vprbrd_iio_read_raw (git-fixes). * iio: adc: xilinx-xadc: Fix sequencer mode in postdisable for dual mux (git- fixes). * iio: buffer: hw-consumer: fix use-after-free in error path (git-fixes). * iio: dac: ad5686: acquire lock when doing powerdown control (git-fixes). * iio: dac: ad5686: fix input raw value check (git-fixes). * iio: dac: max5821: fix return value check in powerdown sync (git-fixes). * iio: gyro: itg3200: fix i2c read into the wrong stack location (git-fixes). * iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer (git-fixes). * iio: light: cm3323: fix reg_conf not being initialized correctly (git- fixes). * iio: magnetometer: st_magn: fix default DRDY pin selection for LIS2MDL (git- fixes). * iio: ssp_sensors: cancel delayed work_refresh on remove (git-fixes). * iio: temperature: tsys01: fix broken PROM checksum validation (git-fixes). * kabi: arm64: module: Update missing .init.text.ftrace_trampoline section message (bsc#1265579 bsc#1265170). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * mmc: core: Fix host controller programming for fixed driver type (git- fixes). * mmc: litex_mmc: Set mandatory idle clocks before CMD0 (git-fixes). * mmc: litex_mmc: Use DIV_ROUND_UP for more accurate clock calculation (git- fixes). * mmc: renesas_sdhi: Add OF entry for RZ/G2H SoC (git-fixes). * mmc: sdhci: add signal voltage switch in sdhci_resume_host (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: gro: do not merge zcopy skbs (git-fixes). * net: mana: Add NULL guards in teardown path to prevent panic on attach failure (git-fixes). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Expose hardware diagnostic info via debugfs (bsc#1266414). * net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer (bsc#1265928). * net: mana: Skip redundant detach on already-detached port (git-fixes). * net: mana: Use kvmalloc for large RX queue and buffer allocations (bsc#1266765). * net: mana: Use per-queue allocation for tx_qp to reduce allocation size (bsc#1266765). * net: mana: hardening: Reject zero max_num_queues from GDMA_QUERY_MAX_RESOURCES (git-fixes). * net: mana: validate rx_req_idx to prevent out-of-bounds array access (bsc#1266402). * net: wwan: iosm: fix potential memory leaks in ipc_imem_init() (git-fixes). * phy: marvell: mvebu-a3700-utmi: fix incorrect USB2_PHY_CTRL register access (git-fixes). * platform/x86: adv_swbutton: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: hp_accel: Check ACPI_COMPANION() against NULL (git-fixes). * platform/x86: intel-hid: Check ACPI_HANDLE() against NULL (git-fixes). * platform/x86: intel-vbtn: Check ACPI_HANDLE() against NULL (git-fixes). * r8152: fix incorrect register write to USB_UPHY_XTAL (git-fixes). * rpm/check-for-config-changes: ignore Rust-related configs (bsc#1258538). * rpm/mkspec: Conditionally set Rust BuildReqs (bsc#1258538). * rpm: Add BuildRequires for Rust enablement (bsc#1258538). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1263068). * s390/entry: Scrub r12 register on kernel entry (bsc#1263068). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1263068). * sched/rt: Skip currently executing CPU in rto_next_cpu() (bsc#1262649). * security/keys: fix missed RCU read section on lookup (stable-fixes). * serial: fsl_lpuart: fix rx buffer and DMA map leaks in start_rx_dma (git- fixes). * serial: qcom-geni: fix UART_RX_PAR_EN bit position (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * smb: client: correctly handle ErrorContextData as a flexible array (git- fixes) * smb: client: reject userspace cifs.spnego descriptions (bsc#1266238). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: mtk-snfi: Fix resource leak in mtk_snand_read_page_cache() (git-fixes). * spi: sprd: fix error pointer deref after DMA setup failure (git-fixes). * spi: st-ssc4: switch to use modern name (stable-fixes). * spi: ti-qspi: fix use-after-free after DMA setup failure (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * string: add mem_is_zero() helper to check if memory area is all zeros (stable-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow (git-fixes). * thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() (git- fixes). * tracing: Switch trace_osnoise.c code over to use guard() and __free() (bsc#1262634). * tty: serial: pch_uart: add check for dma_alloc_coherent() (git-fixes). * usb: cdns3: gadget: fix request skipping after clearing halt (git-fixes). * usb: cdns3: plat: fix unbalanced pm_runtime_forbid() call permanently leaks the runtime PM usage counter across bind/unbind cycles (git-fixes). * usb: chipidea: core: convert ci_role_switch to local variable (git-fixes). * usb: dwc2: Fix use after free in debug code (git-fixes). * usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling (git-fixes). * usb: gadget: dummy_hcd: Reject hub port requests for non-existent ports (git-fixes). * usb: gadget: f_fs: copy only received bytes on short ep0 read (git-fixes). * usb: gadget: f_hid: fix device reference leak in hidg_alloc() (git-fixes). * usb: gadget: net2280: Fix double free in probe error path (git-fixes). * usb: usbtmc: check URB actual_length for interrupt-IN notifications (git- fixes). * usb: usbtmc: reject interrupt endpoints with small wMaxPacketSize (git- fixes). * usbip: vudc: Fix use after free bug in vudc_remove due to race condition (git-fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath10k: skip WMI and beacon transmission when device is wedged (git- fixes). * wifi: ath11k: clear shared SRNG pointer state on restart (git-fixes). * wifi: ath11k: fix error path leak in ath11k_tm_cmd_wmi_ftm() (git-fixes). * wifi: ath11k: fix error path leaks in some WMI WOW calls (git-fixes). * wifi: ath11k: fix error path leaks in some WMI calls (git-fixes). * wifi: ath11k: fix peer resolution on rx path when peer_id=0 (git-fixes). * wifi: ath11k: fix use after free in ath11k_dp_rx_msdu_coalesce() (git- fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: advance loop vars in cfg80211_merge_profile() (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: consume only present negotiated TTLM maps (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: nl80211: reject oversized EMA RNR lists (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-498=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * kernel-source-rt-6.4.0-48.1 * kernel-devel-rt-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 x86_64) * kernel-rt-debugsource-6.4.0-48.1 * kernel-rt-debuginfo-6.4.0-48.1 * kernel-rt-devel-6.4.0-48.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-48.1 * kernel-rt-livepatch-6.4.0-48.1 * SUSE Linux Micro 6.1 (aarch64 nosrc x86_64) * kernel-rt-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-38549.html * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-23303.html * https://www.suse.com/security/cve/CVE-2026-23327.html * https://www.suse.com/security/cve/CVE-2026-23359.html * https://www.suse.com/security/cve/CVE-2026-23438.html * https://www.suse.com/security/cve/CVE-2026-23444.html * https://www.suse.com/security/cve/CVE-2026-31396.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31446.html * https://www.suse.com/security/cve/CVE-2026-31448.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31454.html * https://www.suse.com/security/cve/CVE-2026-31455.html * https://www.suse.com/security/cve/CVE-2026-31464.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31473.html * https://www.suse.com/security/cve/CVE-2026-31480.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31493.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-3150.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31516.html * https://www.suse.com/security/cve/CVE-2026-31518.html * https://www.suse.com/security/cve/CVE-2026-31546.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31590.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31596.html * https://www.suse.com/security/cve/CVE-2026-31613.html * https://www.suse.com/security/cve/CVE-2026-31614.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31655.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31671.html * https://www.suse.com/security/cve/CVE-2026-31673.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31678.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31703.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31767.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43013.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43026.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43030.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43040.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43052.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43054.html * https://www.suse.com/security/cve/CVE-2026-43059.html * https://www.suse.com/security/cve/CVE-2026-43065.html * https://www.suse.com/security/cve/CVE-2026-43066.html * https://www.suse.com/security/cve/CVE-2026-43068.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-43234.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43249.html * https://www.suse.com/security/cve/CVE-2026-43252.html * https://www.suse.com/security/cve/CVE-2026-43261.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43296.html * https://www.suse.com/security/cve/CVE-2026-43325.html * https://www.suse.com/security/cve/CVE-2026-43333.html * https://www.suse.com/security/cve/CVE-2026-43338.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43341.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43359.html * https://www.suse.com/security/cve/CVE-2026-43360.html * https://www.suse.com/security/cve/CVE-2026-43361.html * https://www.suse.com/security/cve/CVE-2026-43362.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43406.html * https://www.suse.com/security/cve/CVE-2026-43407.html * https://www.suse.com/security/cve/CVE-2026-43411.html * https://www.suse.com/security/cve/CVE-2026-43413.html * https://www.suse.com/security/cve/CVE-2026-43414.html * https://www.suse.com/security/cve/CVE-2026-43455.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43470.html * https://www.suse.com/security/cve/CVE-2026-43483.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43499.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45842.html * https://www.suse.com/security/cve/CVE-2026-45843.html * https://www.suse.com/security/cve/CVE-2026-45846.html * https://www.suse.com/security/cve/CVE-2026-45852.html * https://www.suse.com/security/cve/CVE-2026-45856.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45878.html * https://www.suse.com/security/cve/CVE-2026-45886.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45910.html * https://www.suse.com/security/cve/CVE-2026-45932.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45983.html * https://www.suse.com/security/cve/CVE-2026-45984.html * https://www.suse.com/security/cve/CVE-2026-46004.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46021.html * https://www.suse.com/security/cve/CVE-2026-46024.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46043.html * https://www.suse.com/security/cve/CVE-2026-46079.html * https://www.suse.com/security/cve/CVE-2026-46083.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46094.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46110.html * https://www.suse.com/security/cve/CVE-2026-46111.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46114.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46157.html * https://www.suse.com/security/cve/CVE-2026-46159.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46176.html * https://www.suse.com/security/cve/CVE-2026-46181.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46209.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1248235 * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1258538 * https://bugzilla.suse.com/show_bug.cgi?id=1260502 * https://bugzilla.suse.com/show_bug.cgi?id=1260584 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261619 * https://bugzilla.suse.com/show_bug.cgi?id=1261791 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262606 * https://bugzilla.suse.com/show_bug.cgi?id=1262615 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262619 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262622 * https://bugzilla.suse.com/show_bug.cgi?id=1262624 * https://bugzilla.suse.com/show_bug.cgi?id=1262634 * https://bugzilla.suse.com/show_bug.cgi?id=1262649 * https://bugzilla.suse.com/show_bug.cgi?id=1262656 * https://bugzilla.suse.com/show_bug.cgi?id=1262663 * https://bugzilla.suse.com/show_bug.cgi?id=1262668 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262755 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263006 * https://bugzilla.suse.com/show_bug.cgi?id=1263068 * https://bugzilla.suse.com/show_bug.cgi?id=1263115 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263143 * https://bugzilla.suse.com/show_bug.cgi?id=1263152 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263319 * https://bugzilla.suse.com/show_bug.cgi?id=1263562 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263724 * https://bugzilla.suse.com/show_bug.cgi?id=1263769 * https://bugzilla.suse.com/show_bug.cgi?id=1263774 * https://bugzilla.suse.com/show_bug.cgi?id=1263790 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263883 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263932 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263945 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264000 * https://bugzilla.suse.com/show_bug.cgi?id=1264011 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264063 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264093 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264124 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264184 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264243 * https://bugzilla.suse.com/show_bug.cgi?id=1264245 * https://bugzilla.suse.com/show_bug.cgi?id=1264255 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264300 * https://bugzilla.suse.com/show_bug.cgi?id=1264409 * https://bugzilla.suse.com/show_bug.cgi?id=1264430 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264476 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264551 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264669 * https://bugzilla.suse.com/show_bug.cgi?id=1264671 * https://bugzilla.suse.com/show_bug.cgi?id=1264672 * https://bugzilla.suse.com/show_bug.cgi?id=1264716 * https://bugzilla.suse.com/show_bug.cgi?id=1264719 * https://bugzilla.suse.com/show_bug.cgi?id=1264720 * https://bugzilla.suse.com/show_bug.cgi?id=1264722 * https://bugzilla.suse.com/show_bug.cgi?id=1264726 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264765 * https://bugzilla.suse.com/show_bug.cgi?id=1264805 * https://bugzilla.suse.com/show_bug.cgi?id=1264989 * https://bugzilla.suse.com/show_bug.cgi?id=1265020 * https://bugzilla.suse.com/show_bug.cgi?id=1265044 * https://bugzilla.suse.com/show_bug.cgi?id=1265073 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265110 * https://bugzilla.suse.com/show_bug.cgi?id=1265128 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265170 * https://bugzilla.suse.com/show_bug.cgi?id=1265240 * https://bugzilla.suse.com/show_bug.cgi?id=1265579 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1265960 * https://bugzilla.suse.com/show_bug.cgi?id=1266001 * https://bugzilla.suse.com/show_bug.cgi?id=1266009 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266238 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266307 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266394 * https://bugzilla.suse.com/show_bug.cgi?id=1266395 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266400 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266414 * https://bugzilla.suse.com/show_bug.cgi?id=1266452 * https://bugzilla.suse.com/show_bug.cgi?id=1266696 * https://bugzilla.suse.com/show_bug.cgi?id=1266697 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266711 * https://bugzilla.suse.com/show_bug.cgi?id=1266720 * https://bugzilla.suse.com/show_bug.cgi?id=1266759 * https://bugzilla.suse.com/show_bug.cgi?id=1266765 * https://bugzilla.suse.com/show_bug.cgi?id=1266767 * https://bugzilla.suse.com/show_bug.cgi?id=1266810 * https://bugzilla.suse.com/show_bug.cgi?id=1266816 * https://bugzilla.suse.com/show_bug.cgi?id=1266826 * https://bugzilla.suse.com/show_bug.cgi?id=1266827 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266889 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266901 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266927 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1266972 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267214 * https://bugzilla.suse.com/show_bug.cgi?id=1267218 * https://bugzilla.suse.com/show_bug.cgi?id=1267220 * https://bugzilla.suse.com/show_bug.cgi?id=1267222 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267626 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267652 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267663 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267726 * https://bugzilla.suse.com/show_bug.cgi?id=1267732 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:19 -0000 Subject: SUSE-SU-2026:22456-1: important: Security update for docker Message-ID: <178309705977.11236.48174609619094775@4d746be3175e> # Security update for docker Announcement ID: SUSE-SU-2026:22456-1 Release Date: 2026-06-30T11:42:45Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-605=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * docker-debuginfo-29.4.0_ce-slfo.1.1_10.1 * docker-29.4.0_ce-slfo.1.1_10.1 * docker-buildx-0.33.0-slfo.1.1_10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:26 -0000 Subject: SUSE-SU-2026:22455-1: important: Security update for helm Message-ID: <178309706683.11236.3680958981874347267@4d746be3175e> # Security update for helm Announcement ID: SUSE-SU-2026:22455-1 Release Date: 2026-06-30T11:41:55Z Rating: important References: * bsc#1266598 Cross-References: * CVE-2026-39821 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). Changes for helm: * update to 3.21.2: * chore(deps): bump the k8s-io group with 2 updates 1259634 (dependabot[bot]) * fixes b52e276 (Matheus Pimenta) * chore(deps): bump the k8s-io group across 1 directory with 2 updates 3342dbf (dependabot[bot]) * Update to version 3.21.1: * Fixed nil pointer panic that could happen with helm template in ClientOnly flows. Now correctly returns a template error #31920 * Bumped golang.org/x/net to v0.55.0 to address GO-2026-5026 #32152 * Bumped Go from 1.25 to 1.26 #32168 * Dependency version updates * chore(deps): bump oras.land/oras-go/v2 from 2.6.0 to 2.6.1 * chore(deps): bump golang.org/x/crypto from 0.52.0 to 0.53.0 * chore(deps): bump golang.org/x/term from 0.43.0 to 0.44.0 * chore(deps): bump golang.org/x/text from 0.37.0 to 0.38.0 * chore(deps): bump github.com/lib/pq from 1.11.2 to 1.12.3 * chore(deps): bump github.com/distribution/distribution/v3 * chore(deps): bump github.com/containerd/containerd from 1.7.30 to 1.7.32 * chore(deps): bump github.com/Masterminds/semver/v3 from 3.4.0 to 3.5.0 * chore(deps): bump github.com/mattn/go-shellwords from 1.0.12 to 1.0.13 * chore(deps): bump golang.org/x/crypto from 0.51.0 to 0.52.0 * chore(deps): bump k8s.io/klog/v2 from 2.130.1 to 2.140.0 * chore(deps): bump golang.org/x/text from 0.35.0 to 0.37.0 * update golang/x/net to v0.55.0 (bsc#1266598, CVE-2026-39821) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-603=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-slfo.1.1_1.1 * helm-3.21.2-slfo.1.1_1.1 * SUSE Linux Micro 6.1 (noarch) * helm-bash-completion-3.21.2-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:32 -0000 Subject: SUSE-SU-2026:22454-1: important: Security update for dnsmasq Message-ID: <178309707252.11236.8250449246497920083@4d746be3175e> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22454-1 Release Date: 2026-06-30T11:27:04Z Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues Update to 2.93: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-604=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dnsmasq-2.93-slfo.1.1_1.1 * dnsmasq-debuginfo-2.93-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:39 -0000 Subject: SUSE-SU-2026:22453-1: moderate: Security update for glibc Message-ID: <178309707930.11236.6831905657136471077@4d746be3175e> # Security update for glibc Announcement ID: SUSE-SU-2026:22453-1 Release Date: 2026-06-30T09:54:13Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-601=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * glibc-locale-base-2.38-slfo.1.1_9.1 * glibc-devel-2.38-slfo.1.1_9.1 * glibc-2.38-slfo.1.1_9.1 * glibc-debuginfo-2.38-slfo.1.1_9.1 * glibc-debugsource-2.38-slfo.1.1_9.1 * glibc-locale-base-debuginfo-2.38-slfo.1.1_9.1 * glibc-locale-2.38-slfo.1.1_9.1 * glibc-devel-debuginfo-2.38-slfo.1.1_9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:45 -0000 Subject: SUSE-SU-2026:22452-1: moderate: Security update for libslirp Message-ID: <178309708516.11236.39736433101874804@4d746be3175e> # Security update for libslirp Announcement ID: SUSE-SU-2026:22452-1 Release Date: 2026-06-30T09:31:12Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issue * CVE-2026-9539: TCP URG out of bounds heap read information leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-600=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libslirp0-debuginfo-4.8.0+2-slfo.1.1_2.1 * libslirp-debugsource-4.8.0+2-slfo.1.1_2.1 * libslirp0-4.8.0+2-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:52 -0000 Subject: SUSE-SU-2026:22451-1: important: Security update for podman Message-ID: <178309709204.11236.1813256056676570092@4d746be3175e> # Security update for podman Announcement ID: SUSE-SU-2026:22451-1 Release Date: 2026-06-30T09:31:12Z Rating: important References: * bsc#1262856 * bsc#1266125 Cross-References: * CVE-2025-22869 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-52881 * CVE-2025-6032 * CVE-2025-9566 * CVE-2026-34986 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-52881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52881 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52881 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52881 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-6032 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-9566 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-9566 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-9566 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for podman fixes the following issues * CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262856). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266125). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266125). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-598=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * podman-remote-debuginfo-5.4.2-slfo.1.1_5.1 * podmansh-5.4.2-slfo.1.1_5.1 * podman-debuginfo-5.4.2-slfo.1.1_5.1 * podman-5.4.2-slfo.1.1_5.1 * podman-remote-5.4.2-slfo.1.1_5.1 * SUSE Linux Micro 6.1 (noarch) * podman-docker-5.4.2-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-52881.html * https://www.suse.com/security/cve/CVE-2025-6032.html * https://www.suse.com/security/cve/CVE-2025-9566.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262856 * https://bugzilla.suse.com/show_bug.cgi?id=1266125 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:44:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:44:57 -0000 Subject: SUSE-SU-2026:22450-1: important: Security update for krb5 Message-ID: <178309709757.11236.14640003496679138776@4d746be3175e> # Security update for krb5 Announcement ID: SUSE-SU-2026:22450-1 Release Date: 2026-06-30T09:20:36Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-602=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * krb5-client-debuginfo-1.21.3-slfo.1.1_5.1 * krb5-client-1.21.3-slfo.1.1_5.1 * krb5-debugsource-1.21.3-slfo.1.1_5.1 * krb5-1.21.3-slfo.1.1_5.1 * krb5-debuginfo-1.21.3-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:45:03 -0000 Subject: SUSE-SU-2026:22449-1: moderate: Security update for openssl-3 Message-ID: <178309710320.11236.9051814127809240683@4d746be3175e> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:22449-1 Release Date: 2026-06-30T08:42:14Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-599=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-slfo.1.1_11.1 * openssl-3-3.1.4-slfo.1.1_11.1 * libopenssl3-debuginfo-3.1.4-slfo.1.1_11.1 * openssl-3-debugsource-3.1.4-slfo.1.1_11.1 * libopenssl3-3.1.4-slfo.1.1_11.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-slfo.1.1_11.1 * openssl-3-debuginfo-3.1.4-slfo.1.1_11.1 * libopenssl-3-fips-provider-3.1.4-slfo.1.1_11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:45:16 -0000 Subject: SUSE-SU-2026:22447-1: important: Security update for libnfs Message-ID: <178309711660.11236.3093593518503432915@4d746be3175e> # Security update for libnfs Announcement ID: SUSE-SU-2026:22447-1 Release Date: 2026-06-29T10:14:53Z Rating: important References: * bsc#1268135 Cross-References: * CVE-2026-53689 CVSS scores: * CVE-2026-53689 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-53689 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for libnfs fixes the following issue * CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-595=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libnfs14-5.0.2-slfo.1.1_2.1 * libnfs14-debuginfo-5.0.2-slfo.1.1_2.1 * libnfs-debugsource-5.0.2-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53689.html * https://bugzilla.suse.com/show_bug.cgi?id=1268135 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:45:24 -0000 Subject: SUSE-SU-2026:22446-1: important: Security update for dracut Message-ID: <178309712439.11236.13649243888573494863@4d746be3175e> # Security update for dracut Announcement ID: SUSE-SU-2026:22446-1 Release Date: 2026-06-29T09:20:34Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.643.g1f1d880: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-596=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-059+suse.643.g1f1d880-slfo.1.1_1.1 * dracut-fips-059+suse.643.g1f1d880-slfo.1.1_1.1 * dracut-059+suse.643.g1f1d880-slfo.1.1_1.1 * dracut-debugsource-059+suse.643.g1f1d880-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:45:32 -0000 Subject: SUSE-SU-2026:22445-1: important: Security update for python-tornado6 Message-ID: <178309713250.11236.15604743679293589135@4d746be3175e> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:22445-1 Release Date: 2026-06-26T09:54:16Z Rating: important References: * bsc#1268395 * bsc#1268396 * bsc#1268397 Cross-References: * CVE-2026-49853 * CVE-2026-49854 * CVE-2026-49855 CVSS scores: * CVE-2026-49853 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-49854 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-49855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-tornado6 fixes the following issues * CVE-2026-49853: authorization header forwarded across cross-origin redirects in SimpleAsyncHTTPClient (bsc#1268395). * CVE-2026-49854: out-of-bounds memory access via C extension (bsc#1268396). * CVE-2026-49855: AsyncHTTPClient accumulates decompressed chunks without size limit (bsc#1268397). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-593=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.4-slfo.1.1_5.1 * python311-tornado6-6.4-slfo.1.1_5.1 * python-tornado6-debugsource-6.4-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49853.html * https://www.suse.com/security/cve/CVE-2026-49854.html * https://www.suse.com/security/cve/CVE-2026-49855.html * https://bugzilla.suse.com/show_bug.cgi?id=1268395 * https://bugzilla.suse.com/show_bug.cgi?id=1268396 * https://bugzilla.suse.com/show_bug.cgi?id=1268397 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:45:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:45:50 -0000 Subject: SUSE-SU-2026:22443-1: important: Security update for containerd Message-ID: <178309715093.11236.4638837673421231582@4d746be3175e> # Security update for containerd Announcement ID: SUSE-SU-2026:22443-1 Release Date: 2026-06-25T08:46:46Z Rating: important References: * bsc#1262948 * bsc#1265794 * bsc#1266640 Cross-References: * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for containerd fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265794). * CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262948). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-591=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1262948 * https://bugzilla.suse.com/show_bug.cgi?id=1265794 * https://bugzilla.suse.com/show_bug.cgi?id=1266640 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:46:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:46:02 -0000 Subject: SUSE-SU-2026:22442-1: important: Security update for google-guest-agent Message-ID: <178309716215.11236.4666016451700707548@4d746be3175e> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:22442-1 Release Date: 2026-06-24T10:44:18Z Rating: important References: * bsc#1243254 * bsc#1243505 * bsc#1260264 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). Changes: * Update to version 20260529.00 * Dependency updates (#616) * from version 20260522.00 * Fix improper umask calculation on socket creation (#614) * from version 20260520.01 * Update OWNERS (#609) * Bump google.golang.org/grpc from 1.75.0 to 1.79.3 (#602) (bsc#1260264, CVE-2026-33186) * Update to version 20250506.01 (bsc#1243254, bsc#1243505) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-590=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * google-guest-agent-debuginfo-20260529.00-slfo.1.1_1.1 * google-guest-agent-20260529.00-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1243254 * https://bugzilla.suse.com/show_bug.cgi?id=1243505 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:46:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:46:07 -0000 Subject: SUSE-SU-2026:22441-1: important: Security update for sg3_utils Message-ID: <178309716747.11236.11007718345436469744@4d746be3175e> # Security update for sg3_utils Announcement ID: SUSE-SU-2026:22441-1 Release Date: 2026-06-24T08:19:38Z Rating: important References: * bsc#1267823 Affected Products: * SUSE Linux Micro 6.1 An update that has one fix can now be installed. ## Description: This update for sg3_utils fixes the following issue * sg_inq: --export output conformance for SCSI name string and ATA fields (bsc#1267823). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-589=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libsgutils2-1_48-2-debuginfo-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * sg3_utils-debuginfo-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * sg3_utils-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * sg3_utils-debugsource-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 * libsgutils2-1_48-2-1.48~20221101+2.5a7572d6-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267823 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:47:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:47:57 -0000 Subject: SUSE-SU-2026:22440-1: important: Security update for the Linux Kernel Message-ID: <178309727721.11236.2682028425191190395@4d746be3175e> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22440-1 Release Date: 2026-06-30T23:09:03Z Rating: important References: * bsc#1256668 * bsc#1261256 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262620 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263123 * bsc#1263137 * bsc#1263178 * bsc#1263563 * bsc#1263568 * bsc#1263578 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264239 * bsc#1264263 * bsc#1264266 * bsc#1264437 * bsc#1264444 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264741 * bsc#1264763 * bsc#1265103 * bsc#1265143 * bsc#1265628 * bsc#1266290 * bsc#1266390 * bsc#1266397 * bsc#1266698 * bsc#1266704 * bsc#1266705 * bsc#1266878 * bsc#1266895 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266933 * bsc#1267208 * bsc#1267361 * bsc#1267381 * bsc#1267387 * bsc#1267431 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267685 * bsc#1267697 * bsc#1267744 * bsc#1268307 Cross-References: * CVE-2025-10263 * CVE-2025-68822 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31555 * CVE-2026-31592 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31674 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43083 * CVE-2026-43101 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43239 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43469 * CVE-2026-43491 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45894 * CVE-2026-45940 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-46005 * CVE-2026-46037 * CVE-2026-46101 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46172 * CVE-2026-46197 * CVE-2026-46227 * CVE-2026-46244 * CVE-2026-46259 * CVE-2026-46273 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves 71 vulnerabilities and has two fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and 6.1 kernel was updated to receive various security bugfixes. The following security bugs were fixed: * CVE-2025-10263: arm64: errata: Mitigate TLBI errata on various Arm CPUs (bsc#1266290). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: btintel: serialize btintel_hw_error() with hci_req_sync_lock (bsc#1262993). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31664: string.h: Introduce memset_after() for wiping trailing members/padding (bsc#1263578). * CVE-2026-31665: kABI: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: do not dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267387). * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1267651). The following non-security bugs were fixed: * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Do not leave parent IRQ disabled if system_suspend fails (git-fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: Do not set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * X.509: Fix validation of ASN.1 certificate header (git-fixes). * add bugnumber to existing mana_ib change (bsc#1267682) * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-kernel-496=1 ## Package List: * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-48.1 * kernel-obs-build-debugsource-6.4.0-48.1 * kernel-syms-6.4.0-48.1 * SUSE Linux Micro Extras 6.1 (aarch64) * kernel-64kb-debugsource-6.4.0-48.1 * kernel-64kb-devel-6.4.0-48.1 * SUSE Linux Micro Extras 6.1 (nosrc) * kernel-64kb-6.4.0-48.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:48:08 -0000 Subject: SUSE-SU-2026:2747-1: important: Security update for libarchive Message-ID: <178309728840.11236.2211837669114609955@4d746be3175e> # Security update for libarchive Announcement ID: SUSE-SU-2026:2747-1 Release Date: 2026-07-03T11:46:45Z Rating: important References: * bsc#1253088 * bsc#1259928 * bsc#1259931 * bsc#1261186 Cross-References: * CVE-2025-60753 * CVE-2026-4424 * CVE-2026-4426 * CVE-2026-5121 CVSS scores: * CVE-2025-60753 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-60753 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-60753 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4424 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4424 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4424 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4424 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-4426 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4426 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4426 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-5121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-5121 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-5121 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libarchive fixes the following issues * CVE-2025-60753: bsdtar hangs and OOMs with zero-length pattern matches (bsc#1253088). * CVE-2026-4424: information disclosure via heap out-of-bounds read in RAR archive processing (bsc#1259928). * CVE-2026-4426: undefined behavior due to unvalidated operand in shift expression of the zisofs decompression code (bsc#1259931). * CVE-2026-5121: arbitrary code execution via integer overflow in ISO9660 image processing (bsc#1261186). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2747=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2747=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libarchive-debugsource-3.3.3-32.17.1 * libarchive13-3.3.3-32.17.1 * libarchive-devel-3.3.3-32.17.1 * libarchive13-debuginfo-3.3.3-32.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libarchive-debugsource-3.3.3-32.17.1 * libarchive13-3.3.3-32.17.1 * libarchive-devel-3.3.3-32.17.1 * libarchive13-debuginfo-3.3.3-32.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-60753.html * https://www.suse.com/security/cve/CVE-2026-4424.html * https://www.suse.com/security/cve/CVE-2026-4426.html * https://www.suse.com/security/cve/CVE-2026-5121.html * https://bugzilla.suse.com/show_bug.cgi?id=1253088 * https://bugzilla.suse.com/show_bug.cgi?id=1259928 * https://bugzilla.suse.com/show_bug.cgi?id=1259931 * https://bugzilla.suse.com/show_bug.cgi?id=1261186 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:48:13 -0000 Subject: SUSE-SU-2026:2745-1: moderate: Security update for firewalld-legacy Message-ID: <178309729376.11236.3404634425882379798@4d746be3175e> # Security update for firewalld-legacy Announcement ID: SUSE-SU-2026:2745-1 Release Date: 2026-07-03T11:34:34Z Rating: moderate References: * bsc#1260903 Cross-References: * CVE-2026-4948 CVSS scores: * CVE-2026-4948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-4948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for firewalld-legacy fixes the following issue * CVE-2026-4948: local unprivileged users can modify firewall state due to D-Bus setter mis-authorizations (bsc#1260903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2745=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2745=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2745=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2745=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2745=1 ## Package List: * openSUSE Leap 15.6 (noarch) * firewall-applet-1.3.4-150600.13.6.1 * firewalld-1.3.4-150600.13.6.1 * firewalld-lang-1.3.4-150600.13.6.1 * firewall-macros-1.3.4-150600.13.6.1 * python311-firewall-1.3.4-150600.13.6.1 * firewall-config-1.3.4-150600.13.6.1 * firewalld-test-1.3.4-150600.13.6.1 * python3-firewall-1.3.4-150600.13.6.1 * firewalld-zsh-completion-1.3.4-150600.13.6.1 * firewalld-bash-completion-1.3.4-150600.13.6.1 * Basesystem Module 15-SP7 (noarch) * firewalld-1.3.4-150600.13.6.1 * firewalld-lang-1.3.4-150600.13.6.1 * python3-firewall-1.3.4-150600.13.6.1 * firewalld-zsh-completion-1.3.4-150600.13.6.1 * firewalld-bash-completion-1.3.4-150600.13.6.1 * Desktop Applications Module 15-SP7 (noarch) * firewall-applet-1.3.4-150600.13.6.1 * firewall-config-1.3.4-150600.13.6.1 * Python 3 Module 15-SP7 (noarch) * python311-firewall-1.3.4-150600.13.6.1 * Development Tools Module 15-SP7 (noarch) * firewall-macros-1.3.4-150600.13.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4948.html * https://bugzilla.suse.com/show_bug.cgi?id=1260903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:48:19 -0000 Subject: SUSE-SU-2026:2744-1: important: Security update for gstreamer-plugins-bad Message-ID: <178309729983.11236.9730676341041303838@4d746be3175e> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:2744-1 Release Date: 2026-07-03T11:25:07Z Rating: important References: * bsc#1268401 Cross-References: * CVE-2026-52719 CVSS scores: * CVE-2026-52719 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issue * CVE-2026-52719: gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (bsc#1268401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2744=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2744=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2744=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2744=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2744=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2744=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVulkan-1_0-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstTranscoder-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * gstreamer-transcoder-devel-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVulkanXCB-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstVulkanWayland-1_0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-transcoder-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-transcoder-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libgstplay-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-64bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-64bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-64bit-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-64bit-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-64bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-64bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-64bit-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-64bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-64bit-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-64bit-1.24.0-150600.4.6.1 * openSUSE Leap 15.6 (x86_64) * libgstdxva-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-32bit-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstva-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-32bit-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmse-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstplay-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-32bit-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstva-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstmse-1_0-0-32bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-chromaprint-32bit-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-32bit-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-32bit-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-32bit-debuginfo-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-32bit-debuginfo-1.24.0-150600.4.6.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * Desktop Applications Module 15-SP7 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libgsturidownloader-1_0-0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.6.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.6.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.6.1 * libgstva-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-1.24.0-150600.4.6.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * libgstmse-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.6.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstdxva-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.6.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstvulkan-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-1.24.0-150600.4.6.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-1.24.0-150600.4.6.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.6.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.6.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.6.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.6.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.6.1 * libgstmpegts-1_0-0-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstcodecs-1_0-0-1.24.0-150600.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.6.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgstplayer-1_0-0-1.24.0-150600.4.6.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-1.24.0-150600.4.6.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.6.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.6.1 * libgstphotography-1_0-0-1.24.0-150600.4.6.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52719.html * https://bugzilla.suse.com/show_bug.cgi?id=1268401 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:48:26 -0000 Subject: SUSE-SU-2026:2743-1: important: Security update for gstreamer-plugins-bad Message-ID: <178309730600.11236.16285116090758352681@4d746be3175e> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:2743-1 Release Date: 2026-07-03T11:23:55Z Rating: important References: * bsc#1268401 Cross-References: * CVE-2026-52719 CVSS scores: * CVE-2026-52719 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52719 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issue * CVE-2026-52719: gstreamer1-plugins-bad-free: GStreamer: Out-of-bounds read via JPEG segment length validation in VA decoder (bsc#1268401). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2743=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2743=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2743=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2743=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2743=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * gstreamer-transcoder-devel-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-transcoder-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstVulkan-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVulkanXCB-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstTranscoder-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * gstreamer-transcoder-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * typelib-1_0-GstVulkanWayland-1_0-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libgstbadaudio-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-64bit-debuginfo-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-64bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-64bit-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstplay-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-64bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-64bit-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstplay-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-64bit-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-64bit-1.22.0-150500.3.31.1 * openSUSE Leap 15.5 (x86_64) * libgstwayland-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstva-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-32bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-32bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-32bit-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-32bit-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-32bit-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-32bit-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-32bit-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-32bit-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-32bit-1.22.0-150500.3.31.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-bad-chromaprint-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstPlayer-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstMpegts-1_0-1.22.0-150500.3.31.1 * libgstva-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-chromaprint-1.22.0-150500.3.31.1 * typelib-1_0-CudaGst-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstCuda-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstInsertBin-1_0-1.22.0-150500.3.31.1 * typelib-1_0-GstVa-1_0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstCodecs-1_0-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstwayland-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debugsource-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-1.22.0-150500.3.31.1 * libgsttranscoder-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstisoff-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-1.22.0-150500.3.31.1 * libgstcodecparsers-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstbasecamerabinsrc-1_0-0-1.22.0-150500.3.31.1 * libgstwebrtcnice-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstBadAudio-1_0-1.22.0-150500.3.31.1 * libgstwebrtc-1_0-0-1.22.0-150500.3.31.1 * libgstva-1_0-0-debuginfo-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-debuginfo-1.22.0-150500.3.31.1 * libgstphotography-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstinsertbin-1_0-0-debuginfo-1.22.0-150500.3.31.1 * typelib-1_0-GstWebRTC-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcodecs-1_0-0-1.22.0-150500.3.31.1 * libgstbadaudio-1_0-0-1.22.0-150500.3.31.1 * libgstadaptivedemux-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstcuda-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstmpegts-1_0-0-1.22.0-150500.3.31.1 * libgstplay-1_0-0-1.22.0-150500.3.31.1 * libgsturidownloader-1_0-0-1.22.0-150500.3.31.1 * libgstplayer-1_0-0-debuginfo-1.22.0-150500.3.31.1 * libgstvulkan-1_0-0-1.22.0-150500.3.31.1 * typelib-1_0-GstPlay-1_0-1.22.0-150500.3.31.1 * gstreamer-plugins-bad-devel-1.22.0-150500.3.31.1 * libgstsctp-1_0-0-debuginfo-1.22.0-150500.3.31.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-bad-lang-1.22.0-150500.3.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52719.html * https://bugzilla.suse.com/show_bug.cgi?id=1268401 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:48:31 -0000 Subject: SUSE-SU-2026:2742-1: important: Security update for pacemaker Message-ID: <178309731192.11236.6524781618362253283@4d746be3175e> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2742-1 Release Date: 2026-07-03T09:20:51Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issue * CVE-2026-10649: denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-2742=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2742=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * openSUSE Leap 15.4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * pacemaker-remote-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-debugsource-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker3-2.1.2+20211124.ada5c3b36-150400.4.39.1 * libpacemaker-devel-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-remote-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-debuginfo-2.1.2+20211124.ada5c3b36-150400.4.39.1 * pacemaker-cli-2.1.2+20211124.ada5c3b36-150400.4.39.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (noarch) * pacemaker-cts-2.1.2+20211124.ada5c3b36-150400.4.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 16:48:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 16:48:37 -0000 Subject: SUSE-SU-2026:2740-1: moderate: Security update for golang-github-docker-libnetwork Message-ID: <178309731752.11236.8964166729115005162@4d746be3175e> # Security update for golang-github-docker-libnetwork Announcement ID: SUSE-SU-2026:2740-1 Release Date: 2026-07-03T09:07:54Z Rating: moderate References: * bsc#1259566 Cross-References: * CVE-2026-2808 CVSS scores: * CVE-2026-2808 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-2808 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-2808 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for golang-github-docker-libnetwork fixes the following issue * CVE-2026-2808: github.com/hashicorp/consul: unvalidated user-supplied file paths can lead to arbitrary file reads through the Vault Kubernetes authentication provider (bsc#1259566). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2740=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2740=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2740=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2740=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * docker-libnetwork-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 * docker-libnetwork-debuginfo-0.7.0.1+gitr2908_55e924b8-150000.4.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-2808.html * https://bugzilla.suse.com/show_bug.cgi?id=1259566 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 20:30:12 -0000 Subject: SUSE-SU-2026:2751-1: moderate: Security update for tracker-miners Message-ID: <178311061200.273.9064139954204255507@dc2e3449a402> # Security update for tracker-miners Announcement ID: SUSE-SU-2026:2751-1 Release Date: 2026-07-03T13:58:39Z Rating: moderate References: * bsc#1257606 * bsc#1257607 * bsc#1257608 * bsc#1257609 Cross-References: * CVE-2026-1764 * CVE-2026-1765 * CVE-2026-1766 * CVE-2026-1767 CVSS scores: * CVE-2026-1764 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-1764 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1764 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1765 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1765 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1766 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:H * CVE-2026-1767 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.4 An update that solves four vulnerabilities can now be installed. ## Description: This update for tracker-miners fixes the following issues: * CVE-2026-1764: heap buffer overflow leads to denial of service or information disclosure when parsing MP3 files (bsc#1257606). * CVE-2026-1765: denial of service and potential information disclosure via crafted MP3 files (bsc#1257607). * CVE-2026-1766: denial of service and information disclosure via malformed MP3 files (bsc#1257608). * CVE-2026-1767: heap buffer overflow leading to denial of service or information disclosure via malformed MP3 ID3 tags (bsc#1257609). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2751=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * tracker-miner-files-3.2.2-150400.3.10.1 * tracker-miner-files-debuginfo-3.2.2-150400.3.10.1 * tracker-miners-debuginfo-3.2.2-150400.3.10.1 * tracker-miners-debugsource-3.2.2-150400.3.10.1 * tracker-miners-3.2.2-150400.3.10.1 * openSUSE Leap 15.4 (noarch) * tracker-miners-lang-3.2.2-150400.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-1764.html * https://www.suse.com/security/cve/CVE-2026-1765.html * https://www.suse.com/security/cve/CVE-2026-1766.html * https://www.suse.com/security/cve/CVE-2026-1767.html * https://bugzilla.suse.com/show_bug.cgi?id=1257606 * https://bugzilla.suse.com/show_bug.cgi?id=1257607 * https://bugzilla.suse.com/show_bug.cgi?id=1257608 * https://bugzilla.suse.com/show_bug.cgi?id=1257609 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 20:30:20 -0000 Subject: SUSE-SU-2026:2750-1: important: Security update for perl-DBI Message-ID: <178311062099.273.16447151541006158805@dc2e3449a402> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:2750-1 Release Date: 2026-07-03T13:34:24Z Rating: important References: * bsc#1267957 Cross-References: * CVE-2026-9698 CVSS scores: * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-DBI fixes the following issue * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2750=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2750=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2750=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2750=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2750=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2750=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2750=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2750=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-DBI-1.642-150200.3.12.1 * perl-DBI-debugsource-1.642-150200.3.12.1 * perl-DBI-debuginfo-1.642-150200.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 20:30:28 -0000 Subject: SUSE-SU-2026:2749-1: important: Security update for perl-DBI Message-ID: <178311062848.273.3590799450807902969@dc2e3449a402> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:2749-1 Release Date: 2026-07-03T13:04:50Z Rating: important References: * bsc#1267849 * bsc#1267957 Cross-References: * CVE-2026-10879 * CVE-2026-9698 CVSS scores: * CVE-2026-10879 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10879 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10879 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). * CVE-2026-10879: SQL statements with more than 9 binders can cause an heap overflow (bsc#1267849). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2749=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2749=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2749=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2749=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.647.0-150600.12.11.1 * perl-DBI-debugsource-1.647.0-150600.12.11.1 * perl-DBI-debuginfo-1.647.0-150600.12.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10879.html * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267849 * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 3 20:30:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 03 Jul 2026 20:30:34 -0000 Subject: SUSE-SU-2026:2748-1: important: Security update for perl-DBI Message-ID: <178311063497.273.12338677519937883109@dc2e3449a402> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:2748-1 Release Date: 2026-07-03T12:33:43Z Rating: important References: * bsc#1267957 Cross-References: * CVE-2026-9698 CVSS scores: * CVE-2026-9698 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9698 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-DBI fixes the following issue * CVE-2026-9698: DBI versions before 1.648 for Perl saved errors in a limited- sized buffer (bsc#1267957). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2748=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2748=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-DBI-1.628-5.12.1 * perl-DBI-debuginfo-1.628-5.12.1 * perl-DBI-debugsource-1.628-5.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-DBI-1.628-5.12.1 * perl-DBI-debuginfo-1.628-5.12.1 * perl-DBI-debugsource-1.628-5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9698.html * https://bugzilla.suse.com/show_bug.cgi?id=1267957 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 08:30:12 -0000 Subject: SUSE-SU-2026:2758-1: moderate: Security update for python-pip Message-ID: <178332661200.513.6038376696546944429@dc2e3449a402> # Security update for python-pip Announcement ID: SUSE-SU-2026:2758-1 Release Date: 2026-07-03T19:35:52Z Rating: moderate References: * bsc#1262429 * bsc#1263442 Cross-References: * CVE-2026-3219 * CVE-2026-6357 CVSS scores: * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6357 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6357 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2026-6357 ( NVD ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-pip fixes the following issues * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429). * CVE-2026-6357: pip self-update functionality can import newly installed modules after wheel installation (bsc#1263442). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2758=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python3-pip-10.0.1-13.20.1 * python-pip-10.0.1-13.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-6357.html * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1263442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 08:30:17 -0000 Subject: SUSE-SU-2026:2757-1: moderate: Security update for openCryptoki Message-ID: <178332661792.513.18093848684854925847@dc2e3449a402> # Security update for openCryptoki Announcement ID: SUSE-SU-2026:2757-1 Release Date: 2026-07-03T19:29:23Z Rating: moderate References: * bsc#1262283 Cross-References: * CVE-2026-40253 CVSS scores: * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for openCryptoki fixes the following issue: * CVE-2026-40253: malformed BER-encoded cryptographic objects can lead to information disclosure and denial of service (bsc#1262283). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2757=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openCryptoki-64bit-debuginfo-3.26.0-150700.5.17.1 * openCryptoki-64bit-3.26.0-150700.5.17.1 * openCryptoki-devel-3.26.0-150700.5.17.1 * openCryptoki-debugsource-3.26.0-150700.5.17.1 * openCryptoki-debuginfo-3.26.0-150700.5.17.1 * openCryptoki-3.26.0-150700.5.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1262283 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 08:30:23 -0000 Subject: SUSE-SU-2026:2756-1: moderate: Security update for gimp Message-ID: <178332662361.513.8614645112550685527@dc2e3449a402> # Security update for gimp Announcement ID: SUSE-SU-2026:2756-1 Release Date: 2026-07-03T19:25:50Z Rating: moderate References: * bsc#1260837 Cross-References: * CVE-2026-4887 CVSS scores: * CVE-2026-4887 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-4887 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-4887 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gimp fixes the following issue: * CVE-2026-4887: Memory disclosure and denial of service via specially crafted PCX image (bsc#1260837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2756=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2756=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2756=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gimp-2.10.30-150400.3.53.1 * gimp-plugin-aa-2.10.30-150400.3.53.1 * gimp-devel-2.10.30-150400.3.53.1 * libgimpui-2_0-0-2.10.30-150400.3.53.1 * gimp-devel-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.53.1 * gimp-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-2.10.30-150400.3.53.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debugsource-2.10.30-150400.3.53.1 * openSUSE Leap 15.4 (x86_64) * libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.53.1 * libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-32bit-2.10.30-150400.3.53.1 * libgimpui-2_0-0-32bit-2.10.30-150400.3.53.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgimp-2_0-0-64bit-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-64bit-2.10.30-150400.3.53.1 * libgimpui-2_0-0-64bit-2.10.30-150400.3.53.1 * libgimpui-2_0-0-64bit-debuginfo-2.10.30-150400.3.53.1 * openSUSE Leap 15.4 (noarch) * gimp-lang-2.10.30-150400.3.53.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gimp-2.10.30-150400.3.53.1 * gimp-devel-2.10.30-150400.3.53.1 * libgimpui-2_0-0-2.10.30-150400.3.53.1 * gimp-devel-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-2.10.30-150400.3.53.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debugsource-2.10.30-150400.3.53.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch) * gimp-lang-2.10.30-150400.3.53.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * libgimpui-2_0-0-2.10.30-150400.3.53.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debuginfo-2.10.30-150400.3.53.1 * libgimp-2_0-0-2.10.30-150400.3.53.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.53.1 * gimp-debugsource-2.10.30-150400.3.53.1 * SUSE Package Hub 15 15-SP7 (aarch64) * gimp-2.10.30-150400.3.53.1 * gimp-plugin-aa-2.10.30-150400.3.53.1 * gimp-devel-2.10.30-150400.3.53.1 * gimp-devel-debuginfo-2.10.30-150400.3.53.1 * gimp-plugin-aa-debuginfo-2.10.30-150400.3.53.1 * SUSE Package Hub 15 15-SP7 (noarch) * gimp-lang-2.10.30-150400.3.53.1 ## References: * https://www.suse.com/security/cve/CVE-2026-4887.html * https://bugzilla.suse.com/show_bug.cgi?id=1260837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 08:30:31 -0000 Subject: SUSE-SU-2026:2755-1: moderate: Security update for xdg-dbus-proxy Message-ID: <178332663182.513.11675689605120414157@dc2e3449a402> # Security update for xdg-dbus-proxy Announcement ID: SUSE-SU-2026:2755-1 Release Date: 2026-07-03T19:24:13Z Rating: moderate References: * bsc#1261737 Cross-References: * CVE-2026-34080 CVSS scores: * CVE-2026-34080 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34080 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for xdg-dbus-proxy fixes the following issue: * CVE-2026-34080: failure in the policy parser can lead to information disclosure (bsc#1261737). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2755=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2755=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xdg-dbus-proxy-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debuginfo-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debugsource-0.1.5-150600.3.5.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xdg-dbus-proxy-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debuginfo-0.1.5-150600.3.5.1 * xdg-dbus-proxy-debugsource-0.1.5-150600.3.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34080.html * https://bugzilla.suse.com/show_bug.cgi?id=1261737 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 08:30:37 -0000 Subject: SUSE-SU-2026:2754-1: moderate: Security update for python3-lxml Message-ID: <178332663785.513.10617307882601004611@dc2e3449a402> # Security update for python3-lxml Announcement ID: SUSE-SU-2026:2754-1 Release Date: 2026-07-03T19:22:12Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python3-lxml fixes the following issue * CVE-2026-41066: information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2754=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2754=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2754=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-lxml-devel-4.9.1-150500.3.7.1 * python3-lxml-debuginfo-4.9.1-150500.3.7.1 * python3-lxml-debugsource-4.9.1-150500.3.7.1 * python3-lxml-4.9.1-150500.3.7.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * python3-lxml-devel-4.9.1-150500.3.7.1 * python3-lxml-debuginfo-4.9.1-150500.3.7.1 * python3-lxml-debugsource-4.9.1-150500.3.7.1 * python3-lxml-4.9.1-150500.3.7.1 * openSUSE Leap 15.5 (noarch) * python3-lxml-doc-4.9.1-150500.3.7.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-lxml-debuginfo-4.9.1-150500.3.7.1 * python3-lxml-debugsource-4.9.1-150500.3.7.1 * python3-lxml-4.9.1-150500.3.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 08:30:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 08:30:45 -0000 Subject: SUSE-SU-2026:2752-1: moderate: Security update for python3-lxml Message-ID: <178332664598.513.2774383994882185505@dc2e3449a402> # Security update for python3-lxml Announcement ID: SUSE-SU-2026:2752-1 Release Date: 2026-07-03T19:19:50Z Rating: moderate References: * bsc#1263254 Cross-References: * CVE-2026-41066 CVSS scores: * CVE-2026-41066 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41066 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-41066 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python3-lxml fixes the following issue * CVE-2026-41066: Information disclosure via untrusted XML input leading to local file read (bsc#1263254). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2752=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-lxml-3.6.1-3.9.1 * python3-lxml-debuginfo-3.6.1-3.9.1 * python3-lxml-debugsource-3.6.1-3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41066.html * https://bugzilla.suse.com/show_bug.cgi?id=1263254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:30:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:30:11 -0000 Subject: SUSE-SU-2026:2775-1: important: Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes Message-ID: <178334101160.556.3103744981097474039@dc2e3449a402> # Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes Announcement ID: SUSE-SU-2026:2775-1 Release Date: 2026-07-06T07:54:14Z Rating: important References: * bsc#1269253 * bsc#1269534 * jsc#MSQA-1058 Affected Products: * openSUSE Leap 15.4 An update that contains one feature and has two security fixes can now be installed. ## Security update 4.3.19 for Multi-Linux Manager Proxy and Retail Branch Server LTS ### Description: This update fixes the following issues: release-notes-susemanager-proxy: * Update to SUSE Manager 4.3.19 * Bugs mentioned: bsc#1269253, bsc#1269534 ## Security update 4.3.19 for Multi-Linux Manager Server LTS ### Description: This update fixes the following issues: release-notes-susemanager: * Update to SUSE Manager 4.3.19 * Bugs mentioned: bsc#1269253, bsc#1269534 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2775=1 ## Package List: * openSUSE Leap 15.4 (noarch) * release-notes-susemanager-4.3.19-150400.3.157.1 * release-notes-susemanager-proxy-4.3.19-150400.3.113.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://jira.suse.com/browse/MSQA-1058 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:32:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:32:30 -0000 Subject: SUSE-SU-2026:2774-1: important: Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server Message-ID: <178334115020.556.515656939696362363@dc2e3449a402> # Maintenance update for Multi-Linux Manager 5.1: Server, Proxy and Retail Branch Server Announcement ID: SUSE-SU-2026:2774-1 Release Date: 2026-07-06T07:52:26Z Rating: important References: * bsc#1208800 * bsc#1226578 * bsc#1234567 * bsc#1238890 * bsc#1242916 * bsc#1245107 * bsc#1247707 * bsc#1248699 * bsc#1249243 * bsc#1253032 * bsc#1254900 * bsc#1257583 * bsc#1257894 * bsc#1258041 * bsc#1258079 * bsc#1258144 * bsc#1258382 * bsc#1258816 * bsc#1259087 * bsc#1259230 * bsc#1259261 * bsc#1259474 * bsc#1259479 * bsc#1259482 * bsc#1259521 * bsc#1259590 * bsc#1259591 * bsc#1259700 * bsc#1259739 * bsc#1259787 * bsc#1259960 * bsc#1260031 * bsc#1260614 * bsc#1260806 * bsc#1261305 * bsc#1261307 * bsc#1261327 * bsc#1261631 * bsc#1261723 * bsc#1261753 * bsc#1261841 * bsc#1261902 * bsc#1262090 * bsc#1262222 * bsc#1262285 * bsc#1262460 * bsc#1262471 * bsc#1262492 * bsc#1262595 * bsc#1262708 * bsc#1262720 * bsc#1262760 * bsc#1262761 * bsc#1262950 * bsc#1263501 * bsc#1263814 * bsc#1263841 * bsc#1263986 * bsc#1263987 * bsc#1264149 * bsc#1264174 * bsc#1264234 * bsc#1264256 * bsc#1264966 * bsc#1265134 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1265319 * bsc#1265358 * bsc#1265975 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1269253 * bsc#1269534 * jsc#MSQA-1056 * jsc#SUMA-320 Cross-References: * CVE-2022-21698 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-42198 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE * SUSE Multi-Linux Manager Server 5.1 Extension for SLE An update that solves 18 vulnerabilities, contains two features and has 65 security fixes can now be installed. ## Recommended update 5.1.4 for Multi-Linux Manager Proxy ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4: * Bugs mentioned: bsc#1208800, bsc#1234567, bsc#1238890, bsc#1253032, bsc#1257894 bsc#1258382, bsc#1259474, bsc#1259739, bsc#1260806, bsc#1261902 bsc#1262708, bsc#1264966, bsc#1266012 Container images and uyuni-tools changes: proxy-httpd-image, proxy-salt-broker-image, proxy-salt-broker-image, proxy- squid-image, proxy-ssh-image: * Removed unused repositories proxy-tftpd-image: * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Removed unused repositories uyuni-tools: * Version 5.1.29-0 * Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Removed waitForTraefik function (bsc#1261902) * Fixed inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: spacecmd: * Version 5.1.14-0 * Updated translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhanced buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Aligned subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc uyuni-common-libs: * Version 5.1.6-0 * security(checksums): dropped md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager Retail Branch Server ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4: * Bugs mentioned: bsc#1208800, bsc#1234567, bsc#1238890, bsc#1253032, bsc#1257894 bsc#1258382, bsc#1259474, bsc#1259739, bsc#1260806, bsc#1261902 bsc#1262708, bsc#1264966, bsc#1266012 Container images and uyuni-tools changes: proxy-httpd-image, proxy-salt-broker-image, proxy-salt-broker-image, proxy- squid-image, proxy-ssh-image: * Removed unused repositories proxy-tftpd-image: * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Removed unused repositories uyuni-tools: * Version 5.1.29-0 * Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Removed waitForTraefik function (bsc#1261902) * Fixed inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: spacecmd: * Version 5.1.14-0 * Updated translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhanced buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Aligned subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc uyuni-common-libs: * Version 5.1.6-0 * security(checksums): dropped md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgrpxy upgrade podman` which will use the default image tags. ## Security update 5.1.4 for Multi-Linux Manager Server ### Description: This update fixes the following issues: Release Notes Highlights: * Update to SUSE Multi-Linux Manager 5.1.4 * Added note about migration for SUSE Linux Enterprise Server 16 on SSH managed minions * Product Migration from SUSE Linux Enterprise Server 15 SP7 to 16.0 * SUSE Liberty Linux 9.6 Support * New API Endpoint - listMigrationTargetsWithChannels * Debian 12 End-of-Life Notice * SUSE Registry URL Change * Security fixes: CVE-2026-34986, CVE-2026-41602, CVE-2026-39821, CVE-2026-42198 CVE-2022-21698, CVE-2026-40179, CVE-2026-42151, CVE-2026-42154 CVE-2026-28374, CVE-2026-28376, CVE-2026-28379, CVE-2026-28380 CVE-2026-28383, CVE-2026-33376, CVE-2026-33377, CVE-2026-33378 CVE-2026-33380, CVE-2026-33381 * Bugs mentioned: bsc#1226578, bsc#1234567, bsc#1238890, bsc#1242916, bsc#1245107 bsc#1247707, bsc#1248699, bsc#1249243, bsc#1253032, bsc#1257583 bsc#1257894, bsc#1258041, bsc#1258079, bsc#1258144, bsc#1258382 bsc#1258816, bsc#1259087, bsc#1259230, bsc#1259261, bsc#1259474 bsc#1259479, bsc#1259482, bsc#1259521, bsc#1259590, bsc#1259591 bsc#1259700, bsc#1259739, bsc#1259787, bsc#1259960, bsc#1260031 bsc#1260614, bsc#1260806, bsc#1261305, bsc#1261307, bsc#1261327 bsc#1261631, bsc#1261723, bsc#1261753, bsc#1261841, bsc#1261902 bsc#1262090, bsc#1262285, bsc#1262460, bsc#1262471, bsc#1262492 bsc#1262595, bsc#1262708, bsc#1262720, bsc#1262761, bsc#1263814 bsc#1263841, bsc#1264149, bsc#1264234, bsc#1264256, bsc#1264966 bsc#1265134, bsc#1265319, bsc#1265358, bsc#1265975, bsc#1266012 bsc#1262950, bsc#1263501, bsc#1266600, bsc#1266556, bsc#1264174 bsc#1262222, bsc#1263986, bsc#1263987, bsc#1265290, bsc#1265289 bsc#1265288, bsc#1265287, bsc#1265286, bsc#1265285, bsc#1265284 bsc#1265283, bsc#1265282, bsc#1265281, bsc#1269253, bsc#1269534 Container images and uyuni-tools changes: server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Added "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Added support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fixed the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.28-0 * Check access rights on two formula API calls (bsc#1269253) * Sanitize uploaded image name (bsc#1269534) * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fixed CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fixed missing translations (bsc#1259787) * Fixed hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fixed enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fixed Remote Commands hang on direct hostname (bsc#1226578) * Fixed Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Added 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Added missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fixed Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fixed CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fixed conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin ? Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Added missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fixed 2 missing part numbers (bsc#1264256) susemanager: * Version 5.1.17-0 * Added SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Removed spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicensed mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Added Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bcs#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed comamnd for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Added index on rhnPackage (checksum_id) (bsc#1258041) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Added 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Added missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fixed GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fixed CPU reporting for ppc64le clients (bsc#1259521) * Fixed refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Added missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Added SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replaced deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-reportdb-schema: * version 5.1.7-0 * Increased url on table repository (bsc#1259230) uyuni-setup-reportdb: * Version 5.1.5-0 * Fixed delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Dropped SUSECloud module as not longer maintainednor used * Version 1.0.30-0 * No customer facing changes How to apply this update: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run `mgradm upgrade podman` which will use the default image tags. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Server 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Server-SLE-5.1-2026-2774=1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Retail-Branch-Server- SLE-5.1-2026-2774=1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE zypper in -t patch SUSE-Multi-Linux-Manager-Proxy-SLE-5.1-2026-2774=1 ## Package List: * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (noarch) * mgrpxy-lang-5.1.29-150700.3.26.1 * mgrpxy-bash-completion-5.1.29-150700.3.26.1 * mgrpxy-zsh-completion-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-150700.3.26.1 * mgrpxy-debuginfo-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.25 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Proxy 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-ppc64le-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-ppc64le-server-saline-image-5.1.4-9.20.24 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-x86_64-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-x86_64-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (noarch) * mgrctl-zsh-completion-5.1.29-150700.3.26.1 * mgrctl-lang-5.1.29-150700.3.26.1 * mgradm-bash-completion-5.1.29-150700.3.26.1 * mgrctl-bash-completion-5.1.29-150700.3.26.1 * mgradm-zsh-completion-5.1.29-150700.3.26.1 * mgradm-lang-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.29-150700.3.26.1 * mgradm-5.1.29-150700.3.26.1 * mgradm-debuginfo-5.1.29-150700.3.26.1 * mgrctl-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-aarch64-server-postgresql-image-5.1.4-6.24.3 * suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-aarch64-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-aarch64-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image-5.1.4-8.20.13 * SUSE Multi-Linux Manager Server 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-server-saline-image-5.1.4-9.20.24 * suse-multi-linux-manager-5.1-s390x-server-attestation-image-5.1.4-8.22.10 * suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-server-image-5.1.4-8.20.34 * suse-multi-linux-manager-5.1-s390x-server-postgresql-image-5.1.4-6.24.3 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (noarch) * mgrpxy-lang-5.1.29-150700.3.26.1 * mgrpxy-bash-completion-5.1.29-150700.3.26.1 * mgrpxy-zsh-completion-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.12 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.25 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.11 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (aarch64 ppc64le s390x x86_64) * mgrpxy-debuginfo-5.1.29-150700.3.26.1 * mgrpxy-5.1.29-150700.3.26.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 Extension for SLE (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.12 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.13 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.22 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.11 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.25 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-42198.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1226578 * https://bugzilla.suse.com/show_bug.cgi?id=1234567 * https://bugzilla.suse.com/show_bug.cgi?id=1238890 * https://bugzilla.suse.com/show_bug.cgi?id=1242916 * https://bugzilla.suse.com/show_bug.cgi?id=1245107 * https://bugzilla.suse.com/show_bug.cgi?id=1247707 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1249243 * https://bugzilla.suse.com/show_bug.cgi?id=1253032 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257894 * https://bugzilla.suse.com/show_bug.cgi?id=1258041 * https://bugzilla.suse.com/show_bug.cgi?id=1258079 * https://bugzilla.suse.com/show_bug.cgi?id=1258144 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258816 * https://bugzilla.suse.com/show_bug.cgi?id=1259087 * https://bugzilla.suse.com/show_bug.cgi?id=1259230 * https://bugzilla.suse.com/show_bug.cgi?id=1259261 * https://bugzilla.suse.com/show_bug.cgi?id=1259474 * https://bugzilla.suse.com/show_bug.cgi?id=1259479 * https://bugzilla.suse.com/show_bug.cgi?id=1259482 * https://bugzilla.suse.com/show_bug.cgi?id=1259521 * https://bugzilla.suse.com/show_bug.cgi?id=1259590 * https://bugzilla.suse.com/show_bug.cgi?id=1259591 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1259787 * https://bugzilla.suse.com/show_bug.cgi?id=1259960 * https://bugzilla.suse.com/show_bug.cgi?id=1260031 * https://bugzilla.suse.com/show_bug.cgi?id=1260614 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1261305 * https://bugzilla.suse.com/show_bug.cgi?id=1261307 * https://bugzilla.suse.com/show_bug.cgi?id=1261327 * https://bugzilla.suse.com/show_bug.cgi?id=1261631 * https://bugzilla.suse.com/show_bug.cgi?id=1261723 * https://bugzilla.suse.com/show_bug.cgi?id=1261753 * https://bugzilla.suse.com/show_bug.cgi?id=1261841 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262090 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262285 * https://bugzilla.suse.com/show_bug.cgi?id=1262460 * https://bugzilla.suse.com/show_bug.cgi?id=1262471 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262595 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262720 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262761 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263814 * https://bugzilla.suse.com/show_bug.cgi?id=1263841 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1264149 * https://bugzilla.suse.com/show_bug.cgi?id=1264174 * https://bugzilla.suse.com/show_bug.cgi?id=1264234 * https://bugzilla.suse.com/show_bug.cgi?id=1264256 * https://bugzilla.suse.com/show_bug.cgi?id=1264966 * https://bugzilla.suse.com/show_bug.cgi?id=1265134 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1265319 * https://bugzilla.suse.com/show_bug.cgi?id=1265358 * https://bugzilla.suse.com/show_bug.cgi?id=1265975 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1269253 * https://bugzilla.suse.com/show_bug.cgi?id=1269534 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/SUMA-320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:36:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:36:07 -0000 Subject: SUSE-SU-2026:2768-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334136782.556.11623482179143248809@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2768-1 Release Date: 2026-07-06T07:48:37Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1259739 * bsc#1260806 * bsc#1260870 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262222 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1262950 * bsc#1263157 * bsc#1263501 * bsc#1263823 * bsc#1263986 * bsc#1263987 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1266608 * bsc#1267153 * jsc#MSQA-1056 * jsc#PED-14816 Cross-References: * CVE-2022-21698 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-42502 * CVE-2026-42506 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 * SUSE Linux Enterprise Desktop 15 SP1 * SUSE Linux Enterprise Desktop 15 SP2 * SUSE Linux Enterprise Desktop 15 SP3 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 * SUSE Linux Enterprise High Performance Computing 15 SP1 * SUSE Linux Enterprise High Performance Computing 15 SP2 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.0 * SUSE Linux Enterprise Micro 5.1 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP1 * SUSE Linux Enterprise Real Time 15 SP2 * SUSE Linux Enterprise Real Time 15 SP3 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 * SUSE Linux Enterprise Server 15 SP1 * SUSE Linux Enterprise Server 15 SP2 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 * SUSE Linux Enterprise Server for SAP Applications 15 SP1 * SUSE Linux Enterprise Server for SAP Applications 15 SP2 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Multi-Linux Manager Client Tools for SLE 15 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 An update that solves 22 vulnerabilities, contains two features and has 17 security fixes can now be installed. ## Description: This update fixes the following issues: dracut-saltboot updated to version 1.2.1: * Key Update Highlights (v1.2.1) * Added wait check for minion start (default 10s), configurable using rd.saltboot.salt_start_timeout option (bsc#1260870) * Decouple salt key wait check to use separate configurable option rd.saltboot.salt_key_timeout, with default 60s * Introduce rd.saltboot namespace for all options, mark old as deprecated golang-github-QubitProducts-exporter_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-boynux-squid_exporter: * Non customer facing changes golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-alertmanager: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Key Update Highlights (v1.10.0 to v1.10.2): * New Collectors: Added new collectors for PCIe devices and swaps. * New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) * Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. * Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. * Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: * Security issues fixed: * CVE-2026-42151: AzureAD remote write: Fixed OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) * CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the limit (v3.5.3) (bsc#1263987) * CVE-2026-40179: UI: Fixed stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222). * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc#1266608) * Other changes: * Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) * Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) * Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: * Security issues fixed in v11.6.14+security-04: * CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server?s filesystem (bsc#1265282) * Security issues fixed through backported patches: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) * CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) * CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) mgr-push updated to version 5.2.4: * Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-blackbox_exporter: * Security issues fixed: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) rhnlib updated to version 5.2.5: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) supportutils-plugin-salt: * Non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Fixed Report DB CA certificate (bsc#1260806) * Removed waitForTraefik function (bsc#1261902) * Key Update Highlights (v5.2.8-0) * Generate service template only after secrets are created * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Use podman secrets for SSL on proxy * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Fixed incorrect package dependencies declaration (bsc#1229105) * Prevent cobbler port from being exposed * Bumped zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes uyuni-common-libs updated to version 5.2.5: * Key Update Highlights (v5.2.5-0): * Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly * Other changes: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-Micro-5-2026-2768=1 * SUSE Multi-Linux Manager Client Tools for SLE 15 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-15-2026-2768=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.12-150002.3.17.1 * golang-github-prometheus-node_exporter-1.10.2-150002.3.6.2 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-150002.3.6.2 * mgrctl-debuginfo-5.2.12-150002.3.17.1 * SUSE Multi-Linux Manager Client Tools for SLE Micro 5 (noarch) * mgrctl-zsh-completion-5.2.12-150002.3.17.1 * mgrctl-lang-5.2.12-150002.3.17.1 * dracut-saltboot-1.2.1-150002.3.9.1 * mgrctl-bash-completion-5.2.12-150002.3.17.1 * SUSE Multi-Linux Manager Client Tools for SLE 15 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-1.10.2-150002.3.6.2 * prometheus-blackbox_exporter-0.26.0-150002.3.11.1 * grafana-debuginfo-11.6.14+security04-150002.4.21.1 * golang-github-prometheus-prometheus-debuginfo-3.5.3-150002.3.13.1 * grafana-11.6.14+security04-150002.4.21.1 * golang-github-prometheus-alertmanager-0.28.1-150002.4.11.1 * golang-github-lusitaniae-apache_exporter-debuginfo-1.0.10-150002.3.9.2 * golang-github-prometheus-prometheus-3.5.3-150002.3.13.1 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-150002.3.6.2 * golang-github-QubitProducts-exporter_exporter-0.4.0-150002.3.6.2 * prometheus-postgres_exporter-0.10.1-150002.3.3.2 * golang-github-prometheus-alertmanager-debuginfo-0.28.1-150002.4.11.1 * prometheus-postgres_exporter-debuginfo-0.10.1-150002.3.3.2 * mgrctl-debuginfo-5.2.12-150002.3.17.1 * golang-github-lusitaniae-apache_exporter-1.0.10-150002.3.9.2 * golang-github-boynux-squid_exporter-1.13.0-150002.3.6.2 * firewalld-prometheus-config-0.1-150002.3.13.1 * golang-github-boynux-squid_exporter-debuginfo-1.13.0-150002.3.6.2 * mgrctl-5.2.12-150002.3.17.1 * SUSE Multi-Linux Manager Client Tools for SLE 15 (noarch) * python3-mgr-push-5.2.4-150002.3.9.1 * python3-spacewalk-client-tools-5.2.6-150002.3.9.1 * mgrctl-zsh-completion-5.2.12-150002.3.17.1 * python3-defusedxml-0.7.1-150002.1.3.1 * spacecmd-5.2.8-150002.3.12.1 * supportutils-plugin-susemanager-client-5.2.3-150002.3.9.1 * dracut-saltboot-1.2.1-150002.3.9.1 * python3-uyuni-common-libs-5.2.5-150002.3.6.1 * mgr-push-5.2.4-150002.3.9.1 * mgrctl-bash-completion-5.2.12-150002.3.17.1 * mgrctl-lang-5.2.12-150002.3.17.1 * spacewalk-client-tools-5.2.6-150002.3.9.1 * python3-rhnlib-5.2.5-150002.3.9.1 * supportutils-plugin-salt-1.2.3-150002.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260870 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1266608 * https://bugzilla.suse.com/show_bug.cgi?id=1267153 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-14816 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:36:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:36:51 -0000 Subject: SUSE-SU-2026:2766-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334141105.556.10079236093438114517@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2766-1 Release Date: 2026-07-06T07:47:40Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 Cross-References: * CVE-2022-21698 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 12 * SUSE Linux Enterprise Desktop 12 SP1 * SUSE Linux Enterprise Desktop 12 SP2 * SUSE Linux Enterprise Desktop 12 SP3 * SUSE Linux Enterprise Desktop 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 * SUSE Multi-Linux Manager Client Tools for SLE 12 An update that solves one vulnerability, contains one feature and has 18 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248707) golang-github-boynux-squid_exporter: * Non customer facing changes golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter: * Update to 1.10.2: * [BUGFIX] meminfo: Fix typo in Zswap metric name * Update to 1.10.1: * [BUGFIX] filesystem: Fix mount points being collected multiple times * [BUGFIX] filesystem: Refactor mountinfo parsing (bsc#1261810) * [BUGFIX] meminfo: Add Zswap/Zswapped metrics * Update to 1.10.0: * [CHANGE] mdadm: Use sysfs for RAID metrics * [CHANGE] filesystem: Add erofs in default excluded fs * [CHANGE] tcpstat: Use std lib binary.NativeEndian * [FEATURE] pcidevice: Add new collector for PCIe devices * [FEATURE] systemd: Add Virtualization metrics * [FEATURE] swaps: Add new collector * [ENHANCEMENT] wifi: Add packet received and transmitted metrics * [ENHANCEMENT] filesystem: Take super options into account for read-only * [ENHANCEMENT] pcidevice: Add additional metrics * [ENHANCEMENT] perf: Add tlb_data metrics * [BUGFIX] diskstats: Simplify condition * [BUGFIX] thermal: Sanitize darwin thermal strings * [BUGFIX] cpufreq: Fix: collector enable * [BUGFIX] ethtool: Fix returning 0 for sanitized metrics * [BUGFIX] systemd: Fix logging race mgr-push: * Version 5.2.4-0 * Non customer facing changes * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Non customer facing changes prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) rhnlib: * Version 5.2.5-0 * Non customer facing changes * Version 5.2.4-0 * Non customer facing changes * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Non customer facing changes spacecmd: * Version 5.2.8-0 * Non customer facing changes * Version 5.2.7-0 * Add proxy_container_config_nossl command * Version 5.2.6-0 * Update translation strings * Version 5.2.5-0 * Update translation strings * Version 5.2.4-0 * Update translation strings * Version 5.2.3-0 * Fix typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Version 5.2.2-0 * Update translation strings * Version 5.2.1-0 * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fix methods in api namespace in spacecmd (bsc#1249532) spacewalk-client-tools: * Version 5.2.6-0 * Non customer facing changes * Version 5.2.5-0 * Update translations * Version 5.2.4-0 * Non customer facing changes * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Update translation strings1260806 * Version 5.2.1-0 * Non customer facing changes supportutils-plugin-susemanager-client: * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Non customer facing changes uyuni-tools: * Version 5.2.12-0 * No customer facing changes * Version 5.2.11-0 * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) * Version 5.2.10-0 * Preserve hub replicas during upgrade (bsc#1262708) * Add mgrctl commands "ssh" and "ssh remove_known_host" * Use a startup check with no limit for the main server container bsc#1263157) * Make uyuni-server service dependent on uyuni-db (bsc#1263823) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Update the default tag to 5.1.3.1 (bsc#1262760) * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Use correct CA for Report DB (bsc#1260806) * Version 5.2.9-0 * Do not stop container on health check failure Temporary workaround for bsc#1263157 * Version 5.2.8-0 * Generate service template only after secrets are created * Version 5.2.7-0 * Do not require admin secrets on upgrades (bsc#1262409) * Version 5.2.6-0 * Use podman secrets for SSL on proxy * Fix db online backup with new pg_hba settings * mgrctl copy can now infer target name if not set * No need to expose the cobbler port * Add the TFTP port back to the proxy (bsc#1260905) * Fix the macros in the spec file (bsc#1229105) * Disable TFTP by default on the server * Bump zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one * Version 5.2.5-0 * Remove migrate command * Remove template script from mgradm: use the one in the image * Split the TFTP server into a separate container * Adjust mgrctl server filter to work with the new helm chart labels * Remove hub register command * Remove the Kubernetes install and upgrade from mgrpxy - Version 5.2.4-0 * Move the SSL checks at the begining of the migration * Remove Kubernetes code for the mgrdam * Use single universal image to migrate between PostgreSQL versions * Version 5.2.3-0 * Update translation strings * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Actually use the --dbupgrade-tag parameter when computing the image URL (bsc#1249400) * Detect custom Apache and Squid config in the /etc/uyuni/proxy folder * Fix generated DB certificate subject alternate names * add --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * deprecate --registry uyuni-common-libs: * Version 5.2.5-0 * Remove legacy md5/sha1 fallback imports from checksum module; use hashlib directly * Version 5.2.4-0 * Build uyuni-common-libs noarch * Version 5.2.3-0 * Non customer facing changes * Version 5.2.2-0 * Non customer facing changes * Version 5.2.1-0 * Bump version to 5.2.0 ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SLE 12 zypper in -t patch SUSE-MultiLinuxManagerTools-SLE-12-2026-2766=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 12 (aarch64 ppc64le s390x x86_64) * prometheus-postgres_exporter-0.10.1-120002.3.3.2 * golang-github-prometheus-node_exporter-1.10.2-120002.3.6.3 * mgrctl-debuginfo-5.2.12-120002.3.15.2 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-120002.3.6.3 * golang-github-boynux-squid_exporter-1.13.0-120002.3.6.1 * mgrctl-5.2.12-120002.3.15.2 * prometheus-postgres_exporter-debuginfo-0.10.1-120002.3.3.2 * golang-github-lusitaniae-apache_exporter-debuginfo-1.0.10-120002.3.9.2 * golang-github-QubitProducts-exporter_exporter-0.4.0-120002.3.6.1 * golang-github-lusitaniae-apache_exporter-1.0.10-120002.3.9.2 * golang-github-boynux-squid_exporter-debuginfo-1.13.0-120002.3.6.1 * SUSE Multi-Linux Manager Client Tools for SLE 12 (noarch) * mgr-push-5.2.4-120002.3.9.1 * python-defusedxml-0.6.0-120002.1.3.1 * python2-rhnlib-5.2.5-120002.3.9.1 * mgrctl-lang-5.2.12-120002.3.15.2 * supportutils-plugin-salt-1.2.3-120002.3.3.1 * python2-uyuni-common-libs-5.2.5-120002.3.6.1 * mgrctl-zsh-completion-5.2.12-120002.3.15.2 * spacecmd-5.2.8-120002.3.12.1 * spacewalk-client-tools-5.2.6-120002.3.9.1 * python2-spacewalk-client-tools-5.2.6-120002.3.9.1 * mgrctl-bash-completion-5.2.12-120002.3.15.2 * python2-mgr-push-5.2.4-120002.3.9.1 * supportutils-plugin-susemanager-client-5.2.3-120002.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:37:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:37:16 -0000 Subject: SUSE-SU-2026:2765-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334143635.556.14866131547984762121@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2765-1 Release Date: 2026-07-06T07:47:16Z Rating: important References: * bsc#1227579 * bsc#1235516 * bsc#1236516 * bsc#1238686 * bsc#1248699 * bsc#1248707 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1255418 * bsc#1257583 * bsc#1259700 * bsc#1261810 * jsc#MSQA-1056 * jsc#PED-12485 * jsc#PED-7893 * jsc#PED-7928 Cross-References: * CVE-2022-21698 * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Liberty Linux 7 * SUSE Liberty Linux 7 LTSS * SUSE Liberty Linux LTSS 7 for Oracle Linux * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones An update that solves three vulnerabilities, contains four features and has 10 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issue fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Security issues fixed: * CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) * CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) * Highlights of other changes and bug fixes: * Backward Compatibility and packaging changes: * Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains * Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility * Version 1.10.2: * Fixed typo in Zswap metric name (meminfo) * Version 1.10.1: * Fixed mount points being collected multiple times (filesystem) * Refactored mountinfo parsing (bsc#1261810) * Added Zswap/Zswapped metrics (meminfo) * Version 1.10.0: * New collectors: PCIe devices, swaps * Added systemd virtualization metrics, AIX metrics * WiFi packet metrics, additional PCIe and TLB metrics * Changed mdadm to use sysfs, added erofs to excluded filesystems * Fixed bugs: cpufreq collector, ethtool metrics * Version 1.9.1: * Fixed missing IRQ on older kernels (pressure) * Version 1.9.0 (jsc#PED-12485): * Switched to Go log/slog for logging * Converted meminfo to use procfs library * New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, * Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations * Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing * Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) * Version 1.8.x: * Fixed CPU pressure metric collection, pressure collector nil reference * Version 1.8.0: * New collectors: xfrm (IPsec), watchdog * Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing * Removed caching of os-release file modtime/filename * Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race * Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): * New: CPU vulnerabilities reporting from sysfs * Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats * Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index * Version 1.6.0: * Deprecated ntp and supervisord collectors * Removed bcache cache_readaheads_totals metrics * Improved offline CPU handling (removed metrics for offline CPUs) * New: softirqs collector * Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges * Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts mgr-push updated to version 5.2.4: * Internal updates with no customer facing changes across versions (v5.2.1-0 to v5.2.4-0) prometheus-postgres_exporter: * Security issue fixed: * CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) python-simplejson: * Non customer facing changes rhnlib updated to version 5.2.5: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes spacewalk-client-tools updated to version 5.2.6: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.6-0) uyuni-common-libs updated to version 5.2.5: * Key Update Highlights (v5.2.5-0): * Cleaned up the checksum module by removing legacy MD5/SHA1 fallback imports in favor of using standard hashlib directly * Other changes: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.5-0) venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-RES-7-2026-2765=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (aarch64 ppc64le x86_64) * python-simplejson-3.3.1-70002.1.3.1 * venv-salt-minion-3006.0-70002.5.19.1 * prometheus-postgres_exporter-0.10.1-70002.3.3.3 * golang-github-lusitaniae-apache_exporter-1.0.10-70002.3.9.3 * golang-github-prometheus-node_exporter-1.10.2-70002.3.3.3 * golang-github-QubitProducts-exporter_exporter-0.4.0-70002.3.6.2 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 7, RHEL and clones (noarch) * spacewalk-client-tools-5.2.6-70002.3.9.1 * mgr-push-5.2.4-70002.3.9.2 * python2-rhnlib-5.2.5-70002.3.9.1 * python2-uyuni-common-libs-5.2.5-70002.3.6.1 * spacecmd-5.2.8-70002.3.12.1 * python2-spacewalk-client-tools-5.2.6-70002.3.9.1 * python2-mgr-push-5.2.4-70002.3.9.2 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1235516 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-12485 * https://jira.suse.com/browse/PED-7893 * https://jira.suse.com/browse/PED-7928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:37:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:37:57 -0000 Subject: SUSE-SU-2026:2764-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334147770.556.1054847937050433561@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2764-1 Release Date: 2026-07-06T07:46:41Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1235516 * bsc#1236516 * bsc#1238686 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 * jsc#PED-12485 * jsc#PED-7893 * jsc#PED-7928 Cross-References: * CVE-2022-21698 * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones An update that solves three vulnerabilities, contains four features and has 22 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issue fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Security issues fixed: * CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) * CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) * Highlights of other changes and bug fixes: * Backward Compatibility and packaging changes: * Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains * Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility * Version 1.10.2: * Fixed typo in Zswap metric name (meminfo) * Version 1.10.1: * Fixed mount points being collected multiple times (filesystem) * Refactored mountinfo parsing (bsc#1261810) * Added Zswap/Zswapped metrics (meminfo) * Version 1.10.0: * New collectors: PCIe devices, swaps * Added systemd virtualization metrics, AIX metrics * WiFi packet metrics, additional PCIe and TLB metrics * Changed mdadm to use sysfs, added erofs to excluded filesystems * Fixed bugs: cpufreq collector, ethtool metrics * Version 1.9.1: * Fixed missing IRQ on older kernels (pressure) * Version 1.9.0 (jsc#PED-12485): * Switched to Go log/slog for logging * Converted meminfo to use procfs library * New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, * Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations * Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing * Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) * Version 1.8.x: * Fixed CPU pressure metric collection, pressure collector nil reference * Version 1.8.0: * New collectors: xfrm (IPsec), watchdog * Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing * Removed caching of os-release file modtime/filename * Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race * Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): * New: CPU vulnerabilities reporting from sysfs * Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats * Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index * Version 1.6.0: * Deprecated ntp and supervisord collectors * Removed bcache cache_readaheads_totals metrics * Improved offline CPU handling (removed metrics for offline CPUs) * New: softirqs collector * Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges * Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: * Security Fixes: * CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: * Non customer facing changes spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0) * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-8-2026-2764=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones (noarch) * scap-security-guide-redhat-0.1.79-80002.3.9.6 * mgrctl-zsh-completion-5.2.12-80002.3.12.4 * mgrctl-bash-completion-5.2.12-80002.3.12.4 * spacecmd-5.2.8-80002.3.12.4 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 8, RHEL and clones (aarch64 ppc64le x86_64) * prometheus-postgres_exporter-0.10.1-80002.3.3.6 * mgrctl-5.2.12-80002.3.12.4 * golang-github-prometheus-node_exporter-1.10.2-80002.3.3.6 * golang-github-QubitProducts-exporter_exporter-debuginfo-0.4.0-80002.3.6.6 * golang-github-QubitProducts-exporter_exporter-debugsource-0.4.0-80002.3.6.6 * golang-github-QubitProducts-exporter_exporter-0.4.0-80002.3.6.6 * golang-github-lusitaniae-apache_exporter-1.0.10-80002.3.9.6 * venv-salt-minion-3006.0-80002.5.19.1 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1235516 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-12485 * https://jira.suse.com/browse/PED-7893 * https://jira.suse.com/browse/PED-7928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:38:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:38:44 -0000 Subject: SUSE-SU-2026:2763-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools Message-ID: <178334152456.556.5119429850739014426@dc2e3449a402> # Security update 5.1.4 for Multi-Linux Manager Client Tools Announcement ID: SUSE-SU-2026:2763-1 Release Date: 2026-07-06T07:46:11Z Rating: important References: * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1235516 * bsc#1236516 * bsc#1238686 * bsc#1248699 * bsc#1248707 * bsc#1249400 * bsc#1249532 * bsc#1253174 * bsc#1254900 * bsc#1257583 * bsc#1259700 * bsc#1259739 * bsc#1260806 * bsc#1260905 * bsc#1261810 * bsc#1261902 * bsc#1262409 * bsc#1262708 * bsc#1262760 * bsc#1263157 * bsc#1263823 * bsc#1266012 * jsc#MSQA-1056 * jsc#PED-12485 * jsc#PED-7893 * jsc#PED-7928 Cross-References: * CVE-2022-21698 * CVE-2023-45288 * CVE-2025-22870 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones An update that solves three vulnerabilities, contains four features and has 22 security fixes can now be installed. ## Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issue fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-lusitaniae-apache_exporter: * Non customer facing changes golang-github-prometheus-node_exporter updated to version 1.10.2: * Security issues fixed: * CVE-2025-22870: Fixed potential proxy bypass using IPv6 zone IDs (v1.9.1) (bsc#1238686) * CVE-2023-45288: Close connections when receiving too many headers (v1.9.0) (bsc#1236516) * Highlights of other changes and bug fixes: * Backward Compatibility and packaging changes: * Added compatibility for Go 1.22/1.23 needed in older RHEL toolchains * Pinned golang.org/x/net to v0.37.0 for Go 1.22 compatibility * Version 1.10.2: * Fixed typo in Zswap metric name (meminfo) * Version 1.10.1: * Fixed mount points being collected multiple times (filesystem) * Refactored mountinfo parsing (bsc#1261810) * Added Zswap/Zswapped metrics (meminfo) * Version 1.10.0: * New collectors: PCIe devices, swaps * Added systemd virtualization metrics, AIX metrics * WiFi packet metrics, additional PCIe and TLB metrics * Changed mdadm to use sysfs, added erofs to excluded filesystems * Fixed bugs: cpufreq collector, ethtool metrics * Version 1.9.1: * Fixed missing IRQ on older kernels (pressure) * Version 1.9.0 (jsc#PED-12485): * Switched to Go log/slog for logging * Converted meminfo to use procfs library * New features: filesystem mount info, Btrfs commit stats, interrupt filtering, slabinfo filters, IRQ PSI metrics, hwmon filtering, network interface alias labels, GPU clock frequencies, AIX support, * Enhancements: TCP receive queue drop, block device rotational status, CPU online status, performance optimizations * Fixed: ZFS integer underflow, CPU pressure on limited systems, dataset name parsing * Use systemd-sysusers to configure the user in a dedicated 'system-user-prometheus' subpackage (bsc#1235516) * Version 1.8.x: * Fixed CPU pressure metric collection, pressure collector nil reference * Version 1.8.0: * New collectors: xfrm (IPsec), watchdog * Added CPU vulnerability mitigation labels, TCP out-of-order queue metrics, filesystem device error surfacing * Removed caching of os-release file modtime/filename * Fixed: hwmon nil pointer, ethtool metric sanitization, NetClass data race * Version 1.7.0 (jsc#PED-7893, jsc#PED-7928): * New: CPU vulnerabilities reporting from sysfs * Enhancements: parallelized filesystem stat calls, missing link speeds in ethtool, CPU MHz values, qdisc performance, hwmon filtering, rtnetlink for ARP stats * Fixed: netdev 32-bit fallback, btrfs handle leaks, NFSd v4 index * Version 1.6.0: * Deprecated ntp and supervisord collectors * Removed bcache cache_readaheads_totals metrics * Improved offline CPU handling (removed metrics for offline CPUs) * New: softirqs collector * Enhancements: ZFS zpool states and memory metrics, network interface admin state, CPU frequency governor, reduced btrfs privileges * Fixed: perf tracefs detection, thermal zone noise, Linux aarch64 interrupts prometheus-postgres_exporter: * Security Fixes: * CVE-2022-21698: Fixed denial of service using InstrumentHandlerCounter (bsc#1248699) scap-security-guide: * Non customer facing changes spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes uyuni-tools: uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Fixed Report DB CA certificate (bsc#1260806) * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0) * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones zypper in -t patch SUSE-MultiLinuxManagerTools-EL-9-2026-2763=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (aarch64 ppc64le s390x x86_64) * mgrctl-5.2.12-90002.3.12.1 * golang-github-lusitaniae-apache_exporter-1.0.10-90002.3.9.4 * venv-salt-minion-3006.0-90002.5.19.1 * golang-github-QubitProducts-exporter_exporter-debugsource-0.4.0-90002.3.6.4 * golang-github-QubitProducts-exporter_exporter-0.4.0-90002.3.6.4 * golang-github-QubitProducts-exporter_exporter-debuginfo-0.4.0-90002.3.6.4 * prometheus-postgres_exporter-0.10.1-90002.3.3.4 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (noarch) * spacecmd-5.2.8-90002.3.12.1 * scap-security-guide-redhat-0.1.79-90002.3.9.1 * mgrctl-bash-completion-5.2.12-90002.3.12.1 * mgrctl-zsh-completion-5.2.12-90002.3.12.1 * SUSE Multi-Linux Manager Client Tools for SUSE Liberty Linux 9, RHEL and clones (aarch64 ppc64le x86_64) * golang-github-prometheus-node_exporter-1.10.2-90002.3.3.4 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1235516 * https://bugzilla.suse.com/show_bug.cgi?id=1236516 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-12485 * https://jira.suse.com/browse/PED-7893 * https://jira.suse.com/browse/PED-7928 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:39:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:39:33 -0000 Subject: SUSE-SU-2026:2760-1: important: Security update for libnfs Message-ID: <178334157357.556.6155837999483933157@dc2e3449a402> # Security update for libnfs Announcement ID: SUSE-SU-2026:2760-1 Release Date: 2026-07-06T04:05:32Z Rating: important References: * bsc#1268135 Cross-References: * CVE-2026-53689 CVSS scores: * CVE-2026-53689 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-53689 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libnfs fixes the following issue * CVE-2026-53689: integer overflow during a connection to a crafted NFS server (bsc#1268135). Changes for libnfs: * Add libnfs-CVE-2026-53689.patch: ZDR: check the string size for sanity (bsc#1268135 CVE-2026-53689). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2760=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2760=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2760=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2760=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2760=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2760=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2760=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2760=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2760=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnfs8-1.11.0-150000.3.3.1 * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libnfs-debuginfo-1.11.0-150000.3.3.1 * libnfs8-1.11.0-150000.3.3.1 * libnfs8-debuginfo-1.11.0-150000.3.3.1 * libnfs-devel-1.11.0-150000.3.3.1 * libnfs-debugsource-1.11.0-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53689.html * https://bugzilla.suse.com/show_bug.cgi?id=1268135 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 12:39:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 12:39:55 -0000 Subject: SUSE-SU-2026:2759-1: important: Security update for apache2 Message-ID: <178334159548.556.2356085330243603874@dc2e3449a402> # Security update for apache2 Announcement ID: SUSE-SU-2026:2759-1 Release Date: 2026-07-06T02:04:25Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2759=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2759=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2759=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-prefork-2.4.66-150700.4.23.1 * apache2-debuginfo-2.4.66-150700.4.23.1 * apache2-prefork-debuginfo-2.4.66-150700.4.23.1 * apache2-prefork-debugsource-2.4.66-150700.4.23.1 * apache2-2.4.66-150700.4.23.1 * apache2-debugsource-2.4.66-150700.4.23.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-utils-debuginfo-2.4.66-150700.4.23.1 * apache2-worker-debuginfo-2.4.66-150700.4.23.1 * apache2-worker-2.4.66-150700.4.23.1 * apache2-worker-debugsource-2.4.66-150700.4.23.1 * apache2-devel-2.4.66-150700.4.23.1 * apache2-utils-2.4.66-150700.4.23.1 * apache2-utils-debugsource-2.4.66-150700.4.23.1 * Server Applications Module 15-SP7 (noarch) * apache2-manual-2.4.66-150700.4.23.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-event-debugsource-2.4.66-150700.4.23.1 * apache2-event-2.4.66-150700.4.23.1 * apache2-event-debuginfo-2.4.66-150700.4.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:30:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:30:07 -0000 Subject: SUSE-SU-2026:22510-1: important: Security update for pacemaker Message-ID: <178335540797.4636.13527796026171682789@4d746be3175e> # Security update for pacemaker Announcement ID: SUSE-SU-2026:22510-1 Release Date: 2026-06-29T10:55:21Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1108=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pacemaker-remote-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-remote-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debugsource-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-devel-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pacemaker-schemas-3.0.0+20250218.64cd85422c-160000.4.1 * python3-pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cts-3.0.0+20250218.64cd85422c-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:30:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:30:26 -0000 Subject: SUSE-SU-2026:22509-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178335542671.4636.5205803042214916247@4d746be3175e> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22509-1 Release Date: 2026-06-29T10:33:17Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1106=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1106=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_9-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-debuginfo-3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_9-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-3-160000.1.1 * kernel-livepatch-6_12_0-160000_30-default-debuginfo-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:30:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:30:47 -0000 Subject: SUSE-SU-2026:22508-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178335544728.4636.10160740567420791290@4d746be3175e> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22508-1 Release Date: 2026-06-29T10:26:40Z Rating: important References: * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues The following security issues were fixed: * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1107=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1107=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-3-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-3-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_32-default-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16_Update_11-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_32-default-3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:31:04 -0000 Subject: SUSE-SU-2026:22507-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178335546430.4636.16070081890727833472@4d746be3175e> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22507-1 Release Date: 2026-06-29T07:44:21Z Rating: important References: * bsc#1260907 * bsc#1261640 * bsc#1263088 * bsc#1263108 * bsc#1263902 * bsc#1266229 * bsc#1267625 * bsc#1268282 Cross-References: * CVE-2026-23278 * CVE-2026-31402 * CVE-2026-31504 * CVE-2026-31554 * CVE-2026-31694 * CVE-2026-43503 * CVE-2026-46323 CVSS scores: * CVE-2026-23278 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23278 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31402 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31402 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31504 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31504 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31554 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31554 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31694 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31694 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43503 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43503 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43503 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46323 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities and has one fix can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues The following security issues were fixed: * CVE-2026-23278: netfilter: nf_tables: always walk all pending catchall elements (bsc#1260907). * CVE-2026-31402: nfsd: fix heap overflow in NFSv4.0 LOCK replay cache (bsc#1261640). * CVE-2026-31504: net: fix fanout UAF in packet_release() via NETDEV_UP race (bsc#1263088). * CVE-2026-31554: futex: Require sys_futex_requeue() to have identical flags (bsc#1263108). * CVE-2026-31694: fuse: reject oversized dirents in page cache (bsc#1263902). * CVE-2026-43503: final dirty.frag related fixes (bsc#1266229). * CVE-2026-46323: net: gro: don't merge zcopy skbs (bsc#1268282). * net/sched: fix pedit partial COW leading to page cache (bsc#1267625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1101=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1101=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_26-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-7-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-7-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_26-default-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16_Update_5-debugsource-7-160000.1.1 * kernel-livepatch-6_12_0-160000_26-default-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23278.html * https://www.suse.com/security/cve/CVE-2026-31402.html * https://www.suse.com/security/cve/CVE-2026-31504.html * https://www.suse.com/security/cve/CVE-2026-31554.html * https://www.suse.com/security/cve/CVE-2026-31694.html * https://www.suse.com/security/cve/CVE-2026-43503.html * https://www.suse.com/security/cve/CVE-2026-46323.html * https://bugzilla.suse.com/show_bug.cgi?id=1260907 * https://bugzilla.suse.com/show_bug.cgi?id=1261640 * https://bugzilla.suse.com/show_bug.cgi?id=1263088 * https://bugzilla.suse.com/show_bug.cgi?id=1263108 * https://bugzilla.suse.com/show_bug.cgi?id=1263902 * https://bugzilla.suse.com/show_bug.cgi?id=1266229 * https://bugzilla.suse.com/show_bug.cgi?id=1267625 * https://bugzilla.suse.com/show_bug.cgi?id=1268282 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:31:11 -0000 Subject: SUSE-SU-2026:22506-1: moderate: Security update for lcms2 Message-ID: <178335547125.4636.11913278154434083720@4d746be3175e> # Security update for lcms2 Announcement ID: SUSE-SU-2026:22506-1 Release Date: 2026-07-01T12:17:04Z Rating: moderate References: * bsc#1263703 * bsc#1264994 Cross-References: * CVE-2026-41254 * CVE-2026-42798 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42798 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42798 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for lcms2 fixes the following issues * CVE-2026-41254: integer overflow in CubeSize in cmslut.c (bsc#1264994). * CVE-2026-42798: integer overflow in ParseCube in cmscgats.c (bsc#1263703). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1125=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1125=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * liblcms2-doc-2.16-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * liblcms2-devel-2.16-160000.4.1 * liblcms2-2-2.16-160000.4.1 * liblcms2-2-debuginfo-2.16-160000.4.1 * lcms2-2.16-160000.4.1 * lcms2-debugsource-2.16-160000.4.1 * lcms2-debuginfo-2.16-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * liblcms2-2-2.16-160000.4.1 * liblcms2-2-debuginfo-2.16-160000.4.1 * lcms2-2.16-160000.4.1 * liblcms2-devel-2.16-160000.4.1 * lcms2-debugsource-2.16-160000.4.1 * lcms2-debuginfo-2.16-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * liblcms2-doc-2.16-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-42798.html * https://bugzilla.suse.com/show_bug.cgi?id=1263703 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:31:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:31:28 -0000 Subject: SUSE-SU-2026:22504-1: important: Security update for jackson-annotations, jackson-core, jackson-databind Message-ID: <178335548812.4636.15988601634715014568@4d746be3175e> # Security update for jackson-annotations, jackson-core, jackson-databind Announcement ID: SUSE-SU-2026:22504-1 Release Date: 2026-07-01T09:06:57Z Rating: important References: * bsc#1268603 * bsc#1268897 * bsc#1268898 * bsc#1268899 * bsc#1268902 Cross-References: * CVE-2026-54512 * CVE-2026-54513 * CVE-2026-54514 * CVE-2026-54515 CVSS scores: * CVE-2026-54512 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54512 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54514 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54515 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54515 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for jackson-annotations, jackson-core, jackson-databind fixes the following issues * CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation (bsc#1268897). * CVE-2026-54513: jackson-databind has an array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898). * CVE-2026-54514: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899). * CVE-2026-54515: jackson-databind has case-insensitive deserialization bypasses per-property @JsonIgnoreProperties (bsc#1268902). * document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603). Changes for jackson-annotations: * Update to 2.18.8 * No changes since 2.17.3 Changes for jackson-core: * Update to 2.18.8 * Changes of 2.18.8 * # 1611: Apply number-length validator on streaming integer path of async parser * Changes of 2.18.7 * # 1570: Fail parsing from 'DataInput' if 'StreamReadConstraints .getMaxDocumentLength()' set (bsc#1268603, GHSA-2m67-wjpj-xhg9) * # 1600: Rework 3rd party licenses in jar * # 1602: 'UTF8DataInputJsonParser' needs to enforce 'StreamReadConstraints.maxNameLength' limit * Changes of 2.18.6 * # 1512: Number-parsing fix for 'UTF8DataInputJsonParser' * # 1548: 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer * # 1555: Enforce 'StreamReadConstraints.maxNumberLength' for non-blocking (async) parser * Changes of 2.18.5 * # 1433: 'JsonParser#getNumberType()' throws 'JsonParseException' when the current token is non-numeric instead of returning null * # 1446: Invalid package reference to "java.lang.foreign" from 'com.fasterxml.jackson.core:jackson-core' (from 'FastDoubleParser') * Changes of 2.18.3 * # 1391: Fix issue where the parser can read back old number state when parsing later numbers * # 1397: Jackson changes additional values to infinite in case of special JSON structures and existing infinite values * # 1398: Fix issue that feature COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom characterEscape is used * Changes of 2.18.2 * # 1359: Non-surrogate characters being incorrectly combined when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is enabled * Changes of 2.18.1 * # 1353: Use fastdoubleparser 1.0.90 * Changes of 2.18. * # 223: 'UTF8JsonGenerator' writes supplementary characters as a surrogate pair: should use 4-byte encoding * # 1230: Improve performance of 'float' and 'double' parsing from 'TextBuffer' * # 1251: 'InternCache' replace synchronized with 'ReentrantLock' * the cache size limit is no longer strictly enforced for performance reasons but we should never go far about the limit * # 1252: 'ThreadLocalBufferManager' replace synchronized with 'ReentrantLock' * # 1257: Increase InternCache default max size from 100 to 200 * # 1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool' * # 1264: Rename shaded 'ch.randelshofer:fastdoubleparser' classes to prevent use by downstream consumers * # 1271: Deprecate 'LockFreePool' implementation in 2.18 (remove from 3.0) * # 1274: 'NUL'-corrupted keys, values on JSON serialization * # 1277: Add back Java 22 optimisation in FastDoubleParser * # 1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue() /getDecimalValue()' to avoid String allocation * # 1305: Make helper methods of 'WriterBasedJsonGenerator' non-final to allow overriding * # 1310: Add new 'StreamReadConstraints' ('maxTokenCount') to limit maximum number of Tokens allowed per document# * # 1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal' decoding proble Changes for jackson-databind: * Update to 2.18.8 * Changes of 2.18.8 * # 5950: Improve 'UUIDeserializer' error handling * # 5951: Improve 'InetSocketAddress' deserialization (bsc#1268899, CVE-2026-54514) * # 5969: '@JsonView' by-passed for some "setterless" creator properties * # 5971: '@JsonView' by-passed for unwrapped creator parameters * # 5974: '@JsonIgnore' on Record property ignored with 'PropertyNamingStrategy' * # 5981: 'BasicPolymorphicTypeValidator' setting 'allowIfSubTypeIsArray()' should validate element type (bsc#1268898, CVE-2026-54513) * # 5988: 'PolymorphicTypeValidator' needs to validate generic type parameters too (bsc#1268897, CVE-2026-54512) * # 5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls' fold case using JVM default locale (Turkish-I bug) * Changes of 2.18.4 * # 4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on Record property ignored for deserialization * # 5049: Duplicate creator property "b" (index 0 vs 1) on simple java record * Changes of 2.18.3 * # 4444: The 'KeyDeserializer' specified in the class with '@JsonDeserialize(keyUsing = ...)' is overwritten by the 'KeyDeserializer' specified in the 'ObjectMapper'. * # 4827: Subclassed Throwable deserialization fails since v2.18.0 - no creator index for property 'cause' * # 4844: Fix wrapped array handling wrt 'null' by 'StdDeserializer' * # 4848: Avoid type pollution in 'StringCollectionDeserializer' * # 4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not work with multiple constructors since 2.18 * # 4878: When serializing a Map via Converter(StdDelegatingSerializer), a NullPointerException is thrown due to missing key serializer * # 4908: Deserialization behavior change with @JsonCreator and @ConstructorProperties between 2.17 and 2.18 * # 4917: 'BigDecimal' deserialization issue when using '@JsonCreator' * # 4920: Creator properties are ignored on abstract types when collecting bean properties, breaking AsExternalTypeDeserializer * # 4922: Failing '@JsonMerge' with a custom Map * # 4932: Conversion of 'MissingNode' throws 'JsonProcessingException' * Changes of 2.18.2 * # 4733: Wrong serialization of Type Ids for certain types of Enum values * # 4742: Deserialization with Builder, External type id, '@JsonCreator' failing * # 4777: 'StdValueInstantiator.withArgsCreator' is now set for creators with no arguments * # 4783 Possibly wrong behavior of @JsonMerge * # 4787: Wrong 'String.format()' in 'StdDelegatingDeserializer' hides actual error * # 4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides '@JsonProperty' values * # 4790: Fix '@JsonAnySetter' issue with "setter" method (related to #4639) * # 4807: Improve 'FactoryBasedEnumDeserializer' to work better with XML module * # 4810: Deserialization using '@JsonCreator' with renamed property failing (since 2.18) * Changes of 2.18.1 * # 4508: Deserialized JsonAnySetter field in Kotlin data class is null * # 4639: @JsonAnySetter on field ignoring unrecognized properties if they are declared before the last recognized properties in JSON * # 4718: Should not fail on trying to serialize 'java.time.DateTimeException' * # 4724: Deserialization behavior change with Records, '@JsonCreator' and '@JsonValue' between 2.17 and 2.18 * # 4727: Eclipse having issues due'module-info' class "lost" on 2.18.0 jars * # 4741: When 'Include.NON_DEFAULT' setting is used on POJO, empty values are not included in json if default is 'null' * # 4749: Fixed a problem with 'StdDelegatingSerializer#serializeWithType' looking up the serializer with the wrong argument * Changes of 2.18.0 * # 562: Allow '@JsonAnySetter' to flow through Creators * # 806: Problem with 'NamingStrategy', creator methods with implicit names * # 2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and field level '@JsonProperty' * # 3120: Return 'ListIterator' from 'ArrayNode.elements()' * # 3241: 'constructorDetector' seems to invalidate 'defaultSetterInfo' for nullability * # 3439: Java Record '@JsonAnySetter' value is null after deserialization * # 4085: '@JsonView' does not work on class-level for records * # 4119: Exception when deserialization uses a record with a constructor property with 'access=READ_ONLY' * # 4356: 'BeanDeserializerModifier::updateBuilder()' doesn't work for beans with Creator methods * # 4407: 'null' type id handling does not work with 'writeTypePrefix()' * # 4452: '@JsonProperty' not serializing field names properly on '@JsonCreator' in Record * # 4453: Allow JSON Integer to deserialize into a single-arg constructor of parameter type 'double' * # 4456: Rework locking in 'DeserializerCache' * # 4458: Rework synchronized block from 'BeanDeserializerBase' * # 4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()' method is not called on the serializer * # 4472: Rework synchronized block in 'TypeDeserializerBase' * # 4483: Remove 'final' on method BeanSerializer.serialize() * # 4515: Rewrite Bean Property Introspection logic in Jackson 2.x * # 4545: Unexpected deserialization behavior with '@JsonCreator', '@JsonProperty' and javac '-parameters' * # 4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper .canSerialize()' * # 4580: Add 'MapperFeature .SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator properties' declaration order for sorting * # 4584: Provide extension point for detecting "primary" Constructor for Kotlin (and similar) data classes * # 4602: Possible wrong use of _arrayDelegateDeserializer in BeanDeserializerBase::deserializeFromObjectUsingNonDefault() * # 4617: Record property serialization order not preserved * # 4626: '@JsonIgnore' on Record property ignored for deserialization, if there is getter override * # 4630: '@JsonIncludeProperties', '@JsonIgnoreProperties' ignored when serializing Records, if there is getter override * # 4634: '@JsonAnySetter' not working when annotated on both constructor parameter & field * # 4678: Java records don't serialize with 'MapperFeature .REQUIRE_SETTERS_FOR_GETTERS' * # 4688: Should allow deserializing with no-arg '@JsonCreator(mode = DELEGATING)' * # 4694: Deserializing 'BigDecimal' with large number of decimals result in incorrect value * # 4699: Add extra 'writeNumber()' method in 'TokenBuffer' * # 4709: Add 'JacksonCollectors' with 'toArrayNode()' implementation * Fix #5962: Case-insensitive deserialization may use wrong @JsonIgnoreProperties (bsc#1268902, CVE-2026-54515) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1124=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1124=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * jackson-core-2.18.8-160000.1.1 * jackson-databind-javadoc-2.18.8-160000.1.1 * jackson-databind-2.18.8-160000.1.1 * jackson-annotations-2.18.8-160000.1.1 * jackson-annotations-javadoc-2.18.8-160000.1.1 * jackson-core-javadoc-2.18.8-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jackson-core-2.18.8-160000.1.1 * jackson-databind-javadoc-2.18.8-160000.1.1 * jackson-databind-2.18.8-160000.1.1 * jackson-annotations-2.18.8-160000.1.1 * jackson-annotations-javadoc-2.18.8-160000.1.1 * jackson-core-javadoc-2.18.8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54512.html * https://www.suse.com/security/cve/CVE-2026-54513.html * https://www.suse.com/security/cve/CVE-2026-54514.html * https://www.suse.com/security/cve/CVE-2026-54515.html * https://bugzilla.suse.com/show_bug.cgi?id=1268603 * https://bugzilla.suse.com/show_bug.cgi?id=1268897 * https://bugzilla.suse.com/show_bug.cgi?id=1268898 * https://bugzilla.suse.com/show_bug.cgi?id=1268899 * https://bugzilla.suse.com/show_bug.cgi?id=1268902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:32:11 -0000 Subject: SUSE-SU-2026:22496-1: important: Security update for dnsmasq Message-ID: <178335553192.4636.5690023300524292491@4d746be3175e> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:22496-1 Release Date: 2026-06-29T07:41:58Z Rating: important References: * bsc#1268764 Cross-References: * CVE-2026-12725 * CVE-2026-2291 * CVE-2026-6507 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2291 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-2291 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-2291 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6507 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6507 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues Update to 2.93: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). Changes for dnsmasq: * CVE-2026-12725, bsc#1268764: Heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies. * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. * CVE-2026-2291: Rework storage allocation for domain names. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1102=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1102=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-160000.1.1 * dnsmasq-utils-2.93-160000.1.1 * dnsmasq-2.93-160000.1.1 * dnsmasq-utils-debuginfo-2.93-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dnsmasq-utils-debuginfo-2.93-160000.1.1 * dnsmasq-utils-2.93-160000.1.1 * dnsmasq-2.93-160000.1.1 * dnsmasq-debuginfo-2.93-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-2291.html * https://www.suse.com/security/cve/CVE-2026-6507.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:32:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:32:17 -0000 Subject: SUSE-SU-2026:22495-1: important: Security update for python-mistune Message-ID: <178335553753.4636.13709335564231098231@4d746be3175e> # Security update for python-mistune Announcement ID: SUSE-SU-2026:22495-1 Release Date: 2026-06-29T03:09:12Z Rating: important References: * bsc#1269091 Cross-References: * CVE-2026-49851 CVSS scores: * CVE-2026-49851 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49851 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-49851 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-mistune fixes the following issue * CVE-2026-49851: potential DoS via quadratic-time parsing in parse_link_text (bsc#1269091). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1100=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1100=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-mistune-3.1.3-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-mistune-3.1.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49851.html * https://bugzilla.suse.com/show_bug.cgi?id=1269091 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:35:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:35:27 -0000 Subject: SUSE-SU-2026:22493-1: important: Security update 5.1.4 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178335572779.4636.9610840049511092778@4d746be3175e> # Security update 5.1.4 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22493-1 Release Date: 2026-07-06T08:48:50Z Rating: important References: * bsc#1208800 * bsc#1224788 * bsc#1226578 * bsc#1227579 * bsc#1229105 * bsc#1232641 * bsc#1234567 * bsc#1238890 * bsc#1242916 * bsc#1244925 * bsc#1245107 * bsc#1247707 * bsc#1248699 * bsc#1248707 * bsc#1248848 * bsc#1249243 * bsc#1249400 * bsc#1249532 * bsc#1251305 * bsc#1252974 * bsc#1253032 * bsc#1253174 * bsc#1254400 * bsc#1254401 * bsc#1254866 * bsc#1254867 * bsc#1254900 * bsc#1254997 * bsc#1255418 * bsc#1255764 * bsc#1256070 * bsc#1256331 * bsc#1257029 * bsc#1257031 * bsc#1257041 * bsc#1257042 * bsc#1257044 * bsc#1257046 * bsc#1257100 * bsc#1257108 * bsc#1257181 * bsc#1257583 * bsc#1257894 * bsc#1258041 * bsc#1258079 * bsc#1258144 * bsc#1258382 * bsc#1258816 * bsc#1259087 * bsc#1259230 * bsc#1259240 * bsc#1259261 * bsc#1259474 * bsc#1259479 * bsc#1259482 * bsc#1259521 * bsc#1259590 * bsc#1259591 * bsc#1259611 * bsc#1259630 * bsc#1259700 * bsc#1259734 * bsc#1259735 * bsc#1259739 * bsc#1259787 * bsc#1259804 * bsc#1259808 * bsc#1259960 * bsc#1260026 * bsc#1260031 * bsc#1260589 * bsc#1260614 * bsc#1260806 * bsc#1260905 * bsc#1261305 * bsc#1261307 * bsc#1261327 * bsc#1261631 * bsc#1261723 * bsc#1261753 * bsc#1261810 * bsc#1261841 * bsc#1261902 * bsc#1262222 * bsc#1262285 * bsc#1262409 * bsc#1262460 * bsc#1262471 * bsc#1262492 * bsc#1262595 * bsc#1262708 * bsc#1262720 * bsc#1262760 * bsc#1262761 * bsc#1262950 * bsc#1263157 * bsc#1263501 * bsc#1263814 * bsc#1263823 * bsc#1263841 * bsc#1263986 * bsc#1263987 * bsc#1264149 * bsc#1264234 * bsc#1264256 * bsc#1264966 * bsc#1265134 * bsc#1265281 * bsc#1265282 * bsc#1265283 * bsc#1265284 * bsc#1265285 * bsc#1265286 * bsc#1265287 * bsc#1265288 * bsc#1265289 * bsc#1265290 * bsc#1265319 * bsc#1265358 * bsc#1265975 * bsc#1266012 * bsc#1266556 * bsc#1266600 * bsc#1266608 * bsc#1267153 * bsc#1268381 * jsc#MSQA-1056 * jsc#PED-14816 * jsc#SUMA-320 Cross-References: * CVE-2022-21698 * CVE-2023-52425 * CVE-2024-35195 * CVE-2024-47081 * CVE-2024-52804 * CVE-2025-11468 * CVE-2025-12084 * CVE-2025-12781 * CVE-2025-13462 * CVE-2025-13836 * CVE-2025-13837 * CVE-2025-15282 * CVE-2025-15366 * CVE-2025-15367 * CVE-2025-15444 * CVE-2025-50181 * CVE-2025-6069 * CVE-2025-6075 * CVE-2025-66418 * CVE-2025-66471 * CVE-2025-67724 * CVE-2025-67725 * CVE-2025-67726 * CVE-2025-69277 * CVE-2025-8194 * CVE-2025-8291 * CVE-2026-0672 * CVE-2026-0865 * CVE-2026-10649 * CVE-2026-1299 * CVE-2026-21441 * CVE-2026-2297 * CVE-2026-24049 * CVE-2026-25645 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-27448 * CVE-2026-27459 * CVE-2026-28374 * CVE-2026-28376 * CVE-2026-28379 * CVE-2026-28380 * CVE-2026-28383 * CVE-2026-31958 * CVE-2026-33376 * CVE-2026-33377 * CVE-2026-33378 * CVE-2026-33380 * CVE-2026-33381 * CVE-2026-34986 * CVE-2026-3644 * CVE-2026-39821 * CVE-2026-40179 * CVE-2026-41602 * CVE-2026-42151 * CVE-2026-42154 * CVE-2026-4224 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-4519 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52425 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52425 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-52425 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-35195 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N * CVE-2024-47081 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2024-47081 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-47081 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2024-52804 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-52804 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-52804 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-11468 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-11468 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2025-11468 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-12084 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12084 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-12781 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-12781 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-12781 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-12781 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-13462 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13462 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-13837 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-13837 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13837 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-15282 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15282 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2025-15282 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15366 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15366 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15366 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15367 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-15367 ( SUSE ): 6.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H * CVE-2025-15367 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15444 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2025-15444 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-50181 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-50181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-50181 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-50181 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-6069 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H * CVE-2025-6069 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2025-6069 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-6075 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-6075 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-6075 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-6075 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-66418 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66418 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66418 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66418 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67725 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67725 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67726 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-69277 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-69277 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-69277 ( NVD ): 4.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2025-8194 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-8194 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-8194 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-8291 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-8291 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-8291 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-0672 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0672 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0672 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0865 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0865 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-0865 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-1299 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1299 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-1299 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-21441 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21441 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-21441 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-21441 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21441 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-2297 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-24049 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:P/VC:N/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-24049 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-24049 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-24049 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-24049 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-25645 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-25645 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25645 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-25645 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27448 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27448 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-28374 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-28374 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28374 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-28376 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28376 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28379 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28379 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28380 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-28380 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-28383 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28383 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28383 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33376 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33376 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33376 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33377 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33377 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-33378 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33378 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33378 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33380 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-33380 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-33380 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33381 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33381 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33381 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3644 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3644 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3644 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3644 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-40179 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40179 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-40179 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40179 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42154 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42154 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-4224 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4224 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-4519 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N * CVE-2026-4519 ( SUSE ): 6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N * CVE-2026-4519 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4519 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 * SUSE Linux Micro 6.1 * SUSE Linux Micro 6.2 * SUSE Multi-Linux Manager Client Tools for SLE 16 * SUSE Multi-Linux Manager Proxy 5.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 * SUSE Multi-Linux Manager Server 5.1 An update that solves 61 vulnerabilities, contains three features and has 65 fixes can now be installed. ## Security update 5.1.4 for Multi-Linux Manager Client Tools and Salt Bundle ### Description: This update fixes the following issues: golang-github-QubitProducts-exporter_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) golang-github-prometheus-node_exporter updated to version 1.10.2: * Key Update Highlights (v1.10.0 to v1.10.2): * New Collectors: Added new collectors for PCIe devices and swaps. * New Metrics: Introduced metrics for Zswap/Zswapped, Systemd Virtualization, and WiFi packets (received/transmitted) * Bug Fixes: Resolved a duplicate collection bug in filesystem mount points, fixed a Zswap metric typo, and patched a logging race condition in systemd. * Changes: Switched mdadm to use sysfs for RAID metrics, and added erofs to the default excluded filesystems list. * Internal Refactoring: filesystem mountinfo parsing refactor (bsc#1261810) golang-github-prometheus-prometheus updated to version 3.5.3: * Security issues fixed: * CVE-2026-42151: AzureAD remote write: Fix OAuth client_secret being exposed in plaintext via /-/config endpoint (v3.5.3) (bsc#1263986) * CVE-2026-42154: Remote-read: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) (bsc#1263987) * CVE-2026-40179: UI: Fix stored XSS via unescaped le label values in old UI heatmap chart tick labels (v3.5.2) (bsc#1262222) * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (backported patch) (bsc#1266608) * Other changes: * Remote-Write: Reject snappy-compressed requests whose declared decoded length exceeds the decode limit (v3.5.3) * Use systemd tmpfiles.d to create /var/lib/prometheus hierarchy (jsc#PED-14816) * Internal update with non customer facing changes (v3.5.1) grafana updated to version 11.6.14+security-04: * Security issues fixed in v11.6.14+security-04: * CVE-2026-28374: Fixed insecure direct object reference in Annotations API (bsc#1265290) * CVE-2026-28376: Fixed unbounded memory allocation in Grafana Live push endpoint (bsc#1265289) * CVE-2026-28383: Fixed unbounded memory allocation in Grafana plugin resources (bsc#1265286) * CVE-2026-28380: Fixed broken access control in Snapshot API (bsc#1265287) * CVE-2026-33376: Fixed Auth Proxy IPv6 whitelist bypass (bsc#1265285) * CVE-2026-28379: Fixed viewer-triggered race condition in Grafana Live (bsc#1265288) * CVE-2026-33377: Fixed dashboard Editor Privilege Escalation (bsc#1265284) * CVE-2026-33378: Fixed OOM exception in Grafana Data Source Plugin (bsc#1265283) * CVE-2026-33381: Prevent users from generating Service Account tokens after permissions removal (bsc#1265281) * CVE-2026-33380: Fixed vulnerability in SQL Expressions allowing an authenticated attacker to read arbitrary files from the Grafana server filesystem (bsc#1265282) * Security issues fixed through backported patches: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266600) * CVE-2026-34986: Fixed panic in JWE decryption (bsc#1262950) * CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * CVE-2026-25680, CVE-2026-42502, CVE-2026-27136, CVE-2026-25681, CVE-2026-42506: Fixed multiple issues when parsing HTML files (bsc#1267153) prometheus-blackbox_exporter: * Security issues fixed: * CVE-2026-39821: Fixed validation bypass and privilege escalation by updating golang.org/x/net to version 0.55.0 (bsc#1266556) prometheus-postgres_exporter: * Security issues fixed: * CVE-2022-21698: Fixed prometheus/client_golang possible denial of service using InstrumentHandlerCounter (bsc#1248699) spacecmd updated to version 5.2.8: * Key Update Highlights (v5.2.3-0): * Fixed typo in spacecmd help ca-cert flag (bsc#1253174) * Add subcommand to check if reboot is needed after applying all available patches * Key Update Highlights (v5.2.1-0): * Use JSON instead of pickle for spacecmd cache (bsc#1227579) * Fixed methods in api namespace in spacecmd (bsc#1249532) * Other changes (v5.2.2-0 to 5.2.8-0): * Translation strings updates * Internal updates with non customer facing changes supportutils-plugin-susemanager-client updated to version 5.2.3: * Internal updates with non customer facing changes across versions (v5.2.1-0 to v5.2.3-0) uyuni-tools updated to version 5.2.12: * Key Update Highlights (v5.2.11-0) * Improved pod readiness checks (bsc#1266012) * Key Update Highlights (v5.2.10-0) * Preserve hub replicas during upgrade (bsc#1262708) * Added mgrctl "ssh" and "ssh remove_known_host" commands * Fixed startup checks for main server container (bsc#1263157) * Fixed service dependencies (bsc#1263823) * Updated default tag to 5.1.3.1 (bsc#1262760) * Fixed missing registry for db image (bsc#1259739) * Internal SANs for db and reportdb are no longer required * Generate the same certificate for server and reportdb * Fixed Report DB CA certificate (bsc#1260806) * Removed waitForTraefik function (bsc#1261902) * Key Update Highlights (v5.2.8-0) * Generate service template only after secrets are created * Key Update Highlights (v5.2.7-0) * Admin secrets no longer required on upgrades (bsc#1262409) * Key Update Highlights (v5.2.6-0): * Use podman secrets for SSL on proxy * Fixed database online backup * mgrctl copy command now infers target name automatically * Restored TFTP port to proxy (bsc#1260905) * TFTP disabled by default on server * Fixed incorrect package dependencies declaration (bsc#1229105) * Prevent cobbler port from being exposed * Bumped zerolog to 1.34 * Ignore spacewalk-service stop return code. * Stop automatically unhealthy container * Use container based server setup instead tools bundled one * Key Update Highlights (v5.2.5-0) * Removed migrate command * Removed hub register command * Split TFTP server into separate container * Removed Kubernetes install/upgrade from mgrpxy * Key Update Highlights (v5.2.1-0) * Fixed --dbupgrade-tag parameter (bsc#1249400) * Added --registry-host, --registry-user, --registry-password options * Deprecated --registry option * Added SUSE Linux Enterprise 15 SP7 support * Migrated custom SSL CA certificates (bsc#1232641) * Other changes (v5.2.1-0 to v5.2.12-0): * Translation strings updates * Internal updates with version bump but without customer facing changes venv-salt-minion: * Improved shutdown reliability when the salt-master/minion is terminated * Fixed broken "pkg.info_installed" after migration to salt.utils.timeutil * Calculate UUID grain for Xen PV guests (bsc#1255418) * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) * BDSA-2025-60810: Harden Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) ## Security update for pacemaker ### Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Recommended update 5.1.4 for Multi-Linux Manager ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.1.16 * Remove unused repos proxy-salt-broker-image: * Version 5.1.15 * Remove unused repos proxy-squid-image: * Version 5.1.14 * Remove unused repos proxy-ssh-image: * Version 5.1.14 * Remove unused repos proxy-tftpd-image: * Version 5.1.14 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Remove unused repos server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Add "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Add support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fix the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fix CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fix missing translations (bsc#1259787) * Fix hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fix enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fix Remote Commands hang on direct hostname (bsc#1226578) * Fix Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Add 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Add missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fix Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * Fix non-ASCII em dash in Pbkdf2Sha256Crypt breaking javadoc build with US- ASCII encoding * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fix CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fix conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Add missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fix 2 missing part numbers (bsc#1264256) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager: * Version 5.1.17-0 * Add SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Remove spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicense mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Add Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bsc#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed command for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Add index on rhnPackage (checksum_id) (bsc#1258041) (gh#uyuni- project/uyuni#11585) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Add 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fix GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fix CPU reporting for ppc64le clients (bsc#1259521) * Fix refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Add missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Add SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replace deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-setup-reportdb: * Version 5.1.5-0 * Fix delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Drop SUSECloud module as not longer maintained nor used * Version 1.0.30-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.1.16 * Remove unused repos proxy-salt-broker-image: * Version 5.1.15 * Remove unused repos proxy-squid-image: * Version 5.1.14 * Remove unused repos proxy-ssh-image: * Version 5.1.14 * Remove unused repos proxy-tftpd-image: * Version 5.1.14 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Remove unused repos server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Add "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Add support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fix the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fix CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fix missing translations (bsc#1259787) * Fix hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fix enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fix Remote Commands hang on direct hostname (bsc#1226578) * Fix Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Add 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Add missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fix Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * Fix non-ASCII em dash in Pbkdf2Sha256Crypt breaking javadoc build with US- ASCII encoding * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fix CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fix conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Add missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fix 2 missing part numbers (bsc#1264256) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager: * Version 5.1.17-0 * Add SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Remove spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicense mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Add Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bsc#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed command for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Add index on rhnPackage (checksum_id) (bsc#1258041) (gh#uyuni- project/uyuni#11585) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Add 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fix GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fix CPU reporting for ppc64le clients (bsc#1259521) * Fix refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Add missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Add SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replace deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-setup-reportdb: * Version 5.1.5-0 * Fix delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Drop SUSECloud module as not longer maintained nor used * Version 1.0.30-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. ## Recommended update 5.1.4 for Multi-Linux Manager ### Description: This update fixes the following issues: proxy-httpd-image: * Version 5.1.16 * Remove unused repos proxy-salt-broker-image: * Version 5.1.15 * Remove unused repos proxy-squid-image: * Version 5.1.14 * Remove unused repos proxy-ssh-image: * Version 5.1.14 * Remove unused repos proxy-tftpd-image: * Version 5.1.14 * Use custom entry id for grub saltboot entries (bsc#1258382, bsc#1208800) * Remove unused repos server-attestation-image: * Version 5.1.15 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-hub-xmlrpc-api-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-image: * Version 5.1.15 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add mozilla-nss-sysinit to Dockerfile required for FIPS (bsc#1247707) * Do not get repositories from SCC in the server container (bsc#1242916) * Add "susemanager-tools", "susemanager" and "susemanager-tools-salt" packages to server-image server-migration-14-16-image: * Version 5.1.14 * Image rebuilt to the newest version with updated dependencies for SUSE Multi-Linux Manager 5.1.4 server-postgresql-image: * Version 5.1.13 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add needed pg_hba rules on upgrade (bsc#1262492, bsc#1264149) server-saline-image: * Version 5.1.14 * Use python3*-tornado6 package to make it working with Python 3.11 uyuni-tools: * Version 5.1.29-0 Check backup status only after database is started (bsc#1262492) * Version 5.1.28-0 * Remove waitForTraefik function (bsc#1261902) * Fix inspect: missing registry for db image (bsc#1259739) * Preserve hub replicas during upgrade (bsc#1262708) * Stop automatically unhealthy container * Ignore spacewalk-service stop return code. * Use correct CA for Report DB (bsc#1260806) * Do not call podman healthcheck run to wait for pods to be ready (bsc#1266012) The following packages are underlying build dependencies and system components used by the containers: cobbler: * Added the distro signature for rhel10 (bsc#1265134) liberate-formula: * Version 0.1.4 * No customer facing changes * Version 0.1.3 * Liberate formula support for EL10 (bsc#1265975) prometheus-exporters-formula: * Version 1.4.3 * Add support for Python 3.13 * Drop migrate_formula_data script as it is obsolete prometheus-postgres_exporter: * CVE-2022-21698: Replace github.com/prometheus/client_golang with version 1.11.1 (bsc#1248699) saline: * Update to version 2026.05.18: * Explicitly set port number for Prometheus target * Fix the issue of using non-vendored tornado with Python 3.11 salt: * Use non vendored tornado with Python 3.11 (bsc#1257583, bsc#1259700) saltboot-formula: * Update to version 1.1.0 * When autoselecting saltboot device, ignore cd/dvd (bsc#1259960) spacecmd: * Version 5.1.14-0 * Update translation strings spacewalk-backend: * Version 5.1.17-0 * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Use PBKDF2-SHA256 (600000 iterations) for new password hashes; verify legacy SHA-256 crypt(3) hashes transparently spacewalk-java: * Version 5.1.26-0 * Added listMigrationTargetsWithChannels endpoint to return the valid migration targets channels (jsc#SUMA-320) * Fix CSV export failure on system Details > Custom Info page * Added support for migration from SLES 15 to SLES 16 * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Updated the tab label for eligible subscription systems (bsc#1249243) * Fixed missing field labels in the Create User form. (bsc#1259591) * Enhance buttons readability and consistency across the product * Fix missing translations (bsc#1259787) * Fix hub SCC forwarding registration credential filter (bsc#1260031) * Sanitize inputs to avoid injection in rhn_conf of http proxy settings inputs (bsc#1245107) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Make OIDC JWKS initialization startup-safe * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Run ANALYZE asynchronously after CLM alignment to avoid deadlocks (bsc#1261753) * Fix enforcement of consecutive chars in password policy (bsc#1262761) * Use salt's network module if host or nslookup are not installed (bsc#1262720) * Fix Remote Commands hang on direct hostname (bsc#1226578) * Fix Python SyntaxWarning for invalid escape sequence '\s' in RHUI extract repo data script (bsc#1262595) * Add 'unpushed' to AdvisoryStatus enum to handle EPEL errata with unpushed status (bsc#1264234) * Kickstart profile for RHEL 8 requires venv-salt-minion instead of salt- minion (bsc#1259474) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Remove validation of packages in kickstart profiles which are not supported anymore (bsc#1259474) * Numeric branch names should not be stored in double format (bsc#1258382) * Add missing pxeeventfailed notification message * Do not add non-FQDN hostnames to the proxy fqdn list (bsc#1263841) * Use supscription matcher output for subscription expiration warning (bsc#1257894) * Fix Oval data sync for ubuntu 26.04 (bsc#1265319) * Recognize PBKDF2-SHA256 hashes alongside legacy SHA-256 crypt(3) in the Java password check helpers * Fix non-ASCII em dash in Pbkdf2Sha256Crypt breaking javadoc build with US- ASCII encoding * security(saml2): default signature algorithm to rsa-sha256 (bsc#1234567) * security(tls): remove TLSv1/TLSv1.1, allow TLSv1.3 for SMTP (bsc#1234567) * Fix CSRFTokenValidator FIPS compatibility by using platform-default SecureRandom (bsc#1247707) * Fix conflicting cobbler system migrations spacewalk-web: * Version 5.1.21-0 * UI changes to support migration from SLES 15 to SLES 16 * Fixed issue causing a blank tab to appear in the Image Building Details page (bsc#1253032) * Minor UI improvements and fixed spinning icon glitch in Admin -> Setup Wizard * Fixed an issue where the "Create Token" modal could become unresponsive when opened * Fixed an issue causing all existing tokens to be deleted in a loop * Improved visibility of all parent rows in permissions table * Enhance buttons placement for a more intuitive experience * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Align subscription matching page warning with dashboard warning for expiring subscriptions (bsc#1257894) * Add missing fragment import (bsc#1264966) subscription-matcher: * Version 0.44 * Fix 2 missing part numbers (bsc#1264256) supportutils-plugin-susemanager-client: * Version 5.1.6-0 * No customer facing changes susemanager: * Version 5.1.17-0 * Add SUSE LibertyLinux 9.6 x86_64 bootstrap repository definition * Remove spacewalk-diskcheck enablement * Use correct CA for Report DB (bsc#1260806) * Relicense mgr-salt-ssh under Apache-2.0 and move it to a separated package named susemanager-tools-salt susemanager-build-keys: * Add Nvidia Cuda Tools key Added: nvidia-cudatools-9CD0A493D42D0685.asc susemanager-docs_en: * Updated the supported features table in the Client Configuration Guide to include Red Hat Linux Enterprise 10 and clones * Added documentation on space usage percentage on the server and db container which can be set using DISKCHECKALERT and DISKTHRESHOLD * Added Code 16 to Monitoring documentation (bsc#1263814) * Added documentation for deleting SCAP scan results to Administration Guide (bsc#1262471) * Rephrased instructions for RBAC in Administration Guide (bsc#1258079) * Added troubleshooting section for BTRFS to Administration Guide (bsc#1258816) * Removed mentions of Leap 15.5 and 15.4 and specified SUSE requiring general or LTS support in Client Configuration Guide (bsc#1262285) * Added information about availability of SLE 16 and SL Micro 6.2 support in the product versions 5.1.2 and later (bsc#1260614) * Removed mention of CIS profile (bsc#1262460) * Corrected path for Salt minion in Retail Guide (#1262090) * Added explanation for translating mgradm arguments to YAML in Installation and Upgrade Guide (bsc#1258144) * Removed Google Cloud Compute from PAYG documentation (bsc#1261631) * Added link to proxy creation from client to an existing document in Installation and Upgrade Guide * Updated features table for EL 10 based distributions * Document Debian 13 * Added support for Open Enterprise Server 25.4 * Clarified how to get PTF images in air-gapped setup in Installation and Upgrade Guide (bsc#1261307) * SUSE Multi-Linux Support does not support autoinstallation (bsc#1259261) * Added instructions about accessing git repositories when building images to Administration Guide * Added online database backup instructions to Administration Guide * Fixed command for product deployment in Installation and Upgrade Guide (bsc#1259479) * Added online database backup instructions susemanager-schema: * Version 5.1.19-0 * Added the RBAC mapping for listMigrationTargetsWithChannels end point (jsc#SUMA-320) * Add index on rhnPackage (checksum_id) (bsc#1258041) (gh#uyuni- project/uyuni#11585) * Move Salt > Remote Commands to its own RBAC namespace (bsc#1261305) * Sync package removal permissions in packages API with the Web UI (bsc#1261327) * Add 'unpushed' to rhn_errata_adv_status_ck constraint to allow importing EPEL errata with unpushed status (bsc#1264234) * Healthcheck on disk usage based on taskomatic (bsc#1238890) * Add missing indexes for channels and tokens (bsc#1259590) * Increase source_url on table rhncontentsource (bsc#1259230) susemanager-sls: * Version 5.1.25-0 * Added salt states to support migration from SLES 15 to SLES 16 * Ignore podman interfaces when resolving FQDNs (bsc#1262720) * Fix GPG key import on first key deploy (bsc#1259482) * Use either ansible-core or ansible packages for Ansible Control node, prefer ansible-core (bsc#1259087) * Fix CPU reporting for ppc64le clients (bsc#1259521) * Fix refresh of virtual instance information (bsc#1261723) susemanager-sync-data: * Version 5.1.10-0 * Add missing RES-EMS channel family (bsc#1265358) * Version 5.1.9-0 * Add SUSE Liberty Linux 9.6 x86_64 product entries uyuni-common-libs: * Version 5.1.6-0 * security(checksums): drop md5 and sha1 from checksum choices (bsc#1234567) * Replace deprecated inspect.getargspec with EAFP usedforsecurity detection uyuni-setup-reportdb: * Version 5.1.5-0 * Fix delete of a reportdb user with uyuni-setup-reportdb-user (bsc#1261841) virtual-host-gatherer: * Version 1.0.31-0 * Drop SUSECloud module as not longer maintained nor used * Version 1.0.30-0 * No customer facing changes How to apply this update: SUSE Multi-Linux Manager Server: 1. Log in as root user to the SUSE Multi-Linux Manager Server. 2. Upgrade mgradm and mgrctl. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. SUSE Multi-Linux Manager Proxy / Retail Branch Server: 1. Log in as root user to the SUSE Multi-Linux Manager Proxy / Retail Branch Server. 2. Upgrade mgrpxy. 3. If you are in a disconnected environment, upgrade the image packages. 4. Reboot the system. 5. Run which will use the default image tags. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Proxy 5.1 zypper in -t patch SUSE-Multi-Linux-Manager-5.1-8=1 * SUSE Multi-Linux Manager Server 5.1 zypper in -t patch SUSE-Multi-Linux-Manager-5.1-8=1 SUSE-Multi-Linux- Manager-5.1-8=1 * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1108=1 * SUSE Multi-Linux Manager Client Tools for SLE 16 zypper in -t patch Multi-Linux-ManagerTools-SLE-16-4=1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 zypper in -t patch SUSE-Multi-Linux-Manager-5.1-8=1 SUSE-Multi-Linux- Manager-5.1-8=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SLE 16 (aarch64 s390x x86_64) * golang-github-prometheus-alertmanager-0.28.1-160002.2.1 * grafana-11.6.14+security04-160002.1.1 * golang-github-prometheus-prometheus-3.5.3-160002.1.1 * prometheus-postgres_exporter-debuginfo-0.10.1-160002.2.1 * golang-github-prometheus-alertmanager-debuginfo-0.28.1-160002.2.1 * golang-github-prometheus-prometheus-debuginfo-3.5.3-160002.1.1 * mgrctl-5.2.12-160002.1.1 * venv-salt-minion-3006.0-160002.6.1 * golang-github-QubitProducts-exporter_exporter-0.4.0-160002.3.1 * grafana-debuginfo-11.6.14+security04-160002.1.1 * prometheus-blackbox_exporter-0.26.0-160002.2.1 * golang-github-prometheus-node_exporter-1.10.2-160002.1.1 * mgrctl-debuginfo-5.2.12-160002.1.1 * prometheus-postgres_exporter-0.10.1-160002.2.1 * golang-github-QubitProducts-exporter_exporter-debuginfo-0.4.0-160002.3.1 * prometheus-blackbox_exporter-debuginfo-0.26.0-160002.2.1 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-160002.1.1 * SUSE Multi-Linux Manager Client Tools for SLE 16 (noarch) * mgrctl-zsh-completion-5.2.12-160002.1.1 * mgrctl-lang-5.2.12-160002.1.1 * supportutils-plugin-susemanager-client-5.2.3-160002.1.1 * spacecmd-5.2.8-160002.1.1 * mgrctl-bash-completion-5.2.12-160002.1.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (noarch) * pacemaker-schemas-3.0.0+20250218.64cd85422c-160000.4.1 * python3-pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cts-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * pacemaker-remote-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-remote-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debugsource-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-cli-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-debuginfo-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-devel-3.0.0+20250218.64cd85422c-160000.4.1 * pacemaker-libs-3.0.0+20250218.64cd85422c-160000.4.1 * SUSE Multi-Linux Manager Server 5.1 (s390x) * suse-multi-linux-manager-5.1-s390x-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-s390x-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-s390x-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-s390x-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-s390x-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-s390x-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Server 5.1 (noarch) * mgrctl-bash-completion-5.1.29-slfo.1.1.1 * mgradm-lang-5.1.29-slfo.1.1.1 * mgrctl-lang-5.1.29-slfo.1.1.1 * mgrctl-zsh-completion-5.1.29-slfo.1.1.1 * mgradm-bash-completion-5.1.29-slfo.1.1.1 * mgradm-zsh-completion-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Server 5.1 (x86_64) * suse-multi-linux-manager-5.1-x86_64-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-x86_64-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-x86_64-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-x86_64-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-x86_64-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-x86_64-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Server 5.1 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.29-slfo.1.1.1 * mgrctl-5.1.29-slfo.1.1.1 * mgradm-debuginfo-5.1.29-slfo.1.1.1 * mgradm-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Server 5.1 (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-ppc64le-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-ppc64le-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-ppc64le-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-ppc64le-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-ppc64le-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Server 5.1 (aarch64) * suse-multi-linux-manager-5.1-aarch64-server-postgresql-image-5.1.4-6.22.10 * suse-multi-linux-manager-5.1-aarch64-server-saline-image-5.1.4-9.20.18 * suse-multi-linux-manager-5.1-aarch64-server-attestation-image-5.1.4-8.22.7 * suse-multi-linux-manager-5.1-aarch64-server-image-5.1.4-8.20.25 * suse-multi-linux-manager-5.1-aarch64-server-migration-14-16-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-aarch64-server-hub-xmlrpc-api-image-5.1.4-8.20.9 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (noarch) * mgrpxy-zsh-completion-5.1.29-slfo.1.1.1 * mgrpxy-lang-5.1.29-slfo.1.1.1 * mgrpxy-bash-completion-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-slfo.1.1.1 * mgrpxy-debuginfo-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.17 * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.19 * SUSE Multi-Linux Manager Retail Branch Server 5.1 (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (x86_64) * suse-multi-linux-manager-5.1-x86_64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-x86_64-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-x86_64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-x86_64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-x86_64-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (ppc64le) * suse-multi-linux-manager-5.1-ppc64le-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-ppc64le-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-ppc64le-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-ppc64le-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-ppc64le-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (noarch) * mgrpxy-zsh-completion-5.1.29-slfo.1.1.1 * mgrpxy-bash-completion-5.1.29-slfo.1.1.1 * mgrpxy-lang-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Proxy 5.1 (aarch64 ppc64le s390x x86_64) * mgrpxy-5.1.29-slfo.1.1.1 * mgrpxy-debuginfo-5.1.29-slfo.1.1.1 * SUSE Multi-Linux Manager Proxy 5.1 (s390x) * suse-multi-linux-manager-5.1-s390x-proxy-salt-broker-image-5.1.4-9.20.19 * suse-multi-linux-manager-5.1-s390x-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-s390x-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-s390x-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-s390x-proxy-httpd-image-5.1.4-8.22.17 * SUSE Multi-Linux Manager Proxy 5.1 (aarch64) * suse-multi-linux-manager-5.1-aarch64-proxy-ssh-image-5.1.4-8.20.9 * suse-multi-linux-manager-5.1-aarch64-proxy-squid-image-5.1.4-8.20.8 * suse-multi-linux-manager-5.1-aarch64-proxy-httpd-image-5.1.4-8.22.17 * suse-multi-linux-manager-5.1-aarch64-proxy-tftpd-image-5.1.4-8.20.10 * suse-multi-linux-manager-5.1-aarch64-proxy-salt-broker-image-5.1.4-9.20.19 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://www.suse.com/security/cve/CVE-2023-52425.html * https://www.suse.com/security/cve/CVE-2024-35195.html * https://www.suse.com/security/cve/CVE-2024-47081.html * https://www.suse.com/security/cve/CVE-2024-52804.html * https://www.suse.com/security/cve/CVE-2025-11468.html * https://www.suse.com/security/cve/CVE-2025-12084.html * https://www.suse.com/security/cve/CVE-2025-12781.html * https://www.suse.com/security/cve/CVE-2025-13462.html * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-13837.html * https://www.suse.com/security/cve/CVE-2025-15282.html * https://www.suse.com/security/cve/CVE-2025-15366.html * https://www.suse.com/security/cve/CVE-2025-15367.html * https://www.suse.com/security/cve/CVE-2025-15444.html * https://www.suse.com/security/cve/CVE-2025-50181.html * https://www.suse.com/security/cve/CVE-2025-6069.html * https://www.suse.com/security/cve/CVE-2025-6075.html * https://www.suse.com/security/cve/CVE-2025-66418.html * https://www.suse.com/security/cve/CVE-2025-66471.html * https://www.suse.com/security/cve/CVE-2025-67724.html * https://www.suse.com/security/cve/CVE-2025-67725.html * https://www.suse.com/security/cve/CVE-2025-67726.html * https://www.suse.com/security/cve/CVE-2025-69277.html * https://www.suse.com/security/cve/CVE-2025-8194.html * https://www.suse.com/security/cve/CVE-2025-8291.html * https://www.suse.com/security/cve/CVE-2026-0672.html * https://www.suse.com/security/cve/CVE-2026-0865.html * https://www.suse.com/security/cve/CVE-2026-10649.html * https://www.suse.com/security/cve/CVE-2026-1299.html * https://www.suse.com/security/cve/CVE-2026-21441.html * https://www.suse.com/security/cve/CVE-2026-2297.html * https://www.suse.com/security/cve/CVE-2026-24049.html * https://www.suse.com/security/cve/CVE-2026-25645.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-27448.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-28374.html * https://www.suse.com/security/cve/CVE-2026-28376.html * https://www.suse.com/security/cve/CVE-2026-28379.html * https://www.suse.com/security/cve/CVE-2026-28380.html * https://www.suse.com/security/cve/CVE-2026-28383.html * https://www.suse.com/security/cve/CVE-2026-31958.html * https://www.suse.com/security/cve/CVE-2026-33376.html * https://www.suse.com/security/cve/CVE-2026-33377.html * https://www.suse.com/security/cve/CVE-2026-33378.html * https://www.suse.com/security/cve/CVE-2026-33380.html * https://www.suse.com/security/cve/CVE-2026-33381.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-3644.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-40179.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-42151.html * https://www.suse.com/security/cve/CVE-2026-42154.html * https://www.suse.com/security/cve/CVE-2026-4224.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-4519.html * https://bugzilla.suse.com/show_bug.cgi?id=1208800 * https://bugzilla.suse.com/show_bug.cgi?id=1224788 * https://bugzilla.suse.com/show_bug.cgi?id=1226578 * https://bugzilla.suse.com/show_bug.cgi?id=1227579 * https://bugzilla.suse.com/show_bug.cgi?id=1229105 * https://bugzilla.suse.com/show_bug.cgi?id=1232641 * https://bugzilla.suse.com/show_bug.cgi?id=1234567 * https://bugzilla.suse.com/show_bug.cgi?id=1238890 * https://bugzilla.suse.com/show_bug.cgi?id=1242916 * https://bugzilla.suse.com/show_bug.cgi?id=1244925 * https://bugzilla.suse.com/show_bug.cgi?id=1245107 * https://bugzilla.suse.com/show_bug.cgi?id=1247707 * https://bugzilla.suse.com/show_bug.cgi?id=1248699 * https://bugzilla.suse.com/show_bug.cgi?id=1248707 * https://bugzilla.suse.com/show_bug.cgi?id=1248848 * https://bugzilla.suse.com/show_bug.cgi?id=1249243 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249532 * https://bugzilla.suse.com/show_bug.cgi?id=1251305 * https://bugzilla.suse.com/show_bug.cgi?id=1252974 * https://bugzilla.suse.com/show_bug.cgi?id=1253032 * https://bugzilla.suse.com/show_bug.cgi?id=1253174 * https://bugzilla.suse.com/show_bug.cgi?id=1254400 * https://bugzilla.suse.com/show_bug.cgi?id=1254401 * https://bugzilla.suse.com/show_bug.cgi?id=1254866 * https://bugzilla.suse.com/show_bug.cgi?id=1254867 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1254997 * https://bugzilla.suse.com/show_bug.cgi?id=1255418 * https://bugzilla.suse.com/show_bug.cgi?id=1255764 * https://bugzilla.suse.com/show_bug.cgi?id=1256070 * https://bugzilla.suse.com/show_bug.cgi?id=1256331 * https://bugzilla.suse.com/show_bug.cgi?id=1257029 * https://bugzilla.suse.com/show_bug.cgi?id=1257031 * https://bugzilla.suse.com/show_bug.cgi?id=1257041 * https://bugzilla.suse.com/show_bug.cgi?id=1257042 * https://bugzilla.suse.com/show_bug.cgi?id=1257044 * https://bugzilla.suse.com/show_bug.cgi?id=1257046 * https://bugzilla.suse.com/show_bug.cgi?id=1257100 * https://bugzilla.suse.com/show_bug.cgi?id=1257108 * https://bugzilla.suse.com/show_bug.cgi?id=1257181 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257894 * https://bugzilla.suse.com/show_bug.cgi?id=1258041 * https://bugzilla.suse.com/show_bug.cgi?id=1258079 * https://bugzilla.suse.com/show_bug.cgi?id=1258144 * https://bugzilla.suse.com/show_bug.cgi?id=1258382 * https://bugzilla.suse.com/show_bug.cgi?id=1258816 * https://bugzilla.suse.com/show_bug.cgi?id=1259087 * https://bugzilla.suse.com/show_bug.cgi?id=1259230 * https://bugzilla.suse.com/show_bug.cgi?id=1259240 * https://bugzilla.suse.com/show_bug.cgi?id=1259261 * https://bugzilla.suse.com/show_bug.cgi?id=1259474 * https://bugzilla.suse.com/show_bug.cgi?id=1259479 * https://bugzilla.suse.com/show_bug.cgi?id=1259482 * https://bugzilla.suse.com/show_bug.cgi?id=1259521 * https://bugzilla.suse.com/show_bug.cgi?id=1259590 * https://bugzilla.suse.com/show_bug.cgi?id=1259591 * https://bugzilla.suse.com/show_bug.cgi?id=1259611 * https://bugzilla.suse.com/show_bug.cgi?id=1259630 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259734 * https://bugzilla.suse.com/show_bug.cgi?id=1259735 * https://bugzilla.suse.com/show_bug.cgi?id=1259739 * https://bugzilla.suse.com/show_bug.cgi?id=1259787 * https://bugzilla.suse.com/show_bug.cgi?id=1259804 * https://bugzilla.suse.com/show_bug.cgi?id=1259808 * https://bugzilla.suse.com/show_bug.cgi?id=1259960 * https://bugzilla.suse.com/show_bug.cgi?id=1260026 * https://bugzilla.suse.com/show_bug.cgi?id=1260031 * https://bugzilla.suse.com/show_bug.cgi?id=1260589 * https://bugzilla.suse.com/show_bug.cgi?id=1260614 * https://bugzilla.suse.com/show_bug.cgi?id=1260806 * https://bugzilla.suse.com/show_bug.cgi?id=1260905 * https://bugzilla.suse.com/show_bug.cgi?id=1261305 * https://bugzilla.suse.com/show_bug.cgi?id=1261307 * https://bugzilla.suse.com/show_bug.cgi?id=1261327 * https://bugzilla.suse.com/show_bug.cgi?id=1261631 * https://bugzilla.suse.com/show_bug.cgi?id=1261723 * https://bugzilla.suse.com/show_bug.cgi?id=1261753 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 * https://bugzilla.suse.com/show_bug.cgi?id=1261841 * https://bugzilla.suse.com/show_bug.cgi?id=1261902 * https://bugzilla.suse.com/show_bug.cgi?id=1262222 * https://bugzilla.suse.com/show_bug.cgi?id=1262285 * https://bugzilla.suse.com/show_bug.cgi?id=1262409 * https://bugzilla.suse.com/show_bug.cgi?id=1262460 * https://bugzilla.suse.com/show_bug.cgi?id=1262471 * https://bugzilla.suse.com/show_bug.cgi?id=1262492 * https://bugzilla.suse.com/show_bug.cgi?id=1262595 * https://bugzilla.suse.com/show_bug.cgi?id=1262708 * https://bugzilla.suse.com/show_bug.cgi?id=1262720 * https://bugzilla.suse.com/show_bug.cgi?id=1262760 * https://bugzilla.suse.com/show_bug.cgi?id=1262761 * https://bugzilla.suse.com/show_bug.cgi?id=1262950 * https://bugzilla.suse.com/show_bug.cgi?id=1263157 * https://bugzilla.suse.com/show_bug.cgi?id=1263501 * https://bugzilla.suse.com/show_bug.cgi?id=1263814 * https://bugzilla.suse.com/show_bug.cgi?id=1263823 * https://bugzilla.suse.com/show_bug.cgi?id=1263841 * https://bugzilla.suse.com/show_bug.cgi?id=1263986 * https://bugzilla.suse.com/show_bug.cgi?id=1263987 * https://bugzilla.suse.com/show_bug.cgi?id=1264149 * https://bugzilla.suse.com/show_bug.cgi?id=1264234 * https://bugzilla.suse.com/show_bug.cgi?id=1264256 * https://bugzilla.suse.com/show_bug.cgi?id=1264966 * https://bugzilla.suse.com/show_bug.cgi?id=1265134 * https://bugzilla.suse.com/show_bug.cgi?id=1265281 * https://bugzilla.suse.com/show_bug.cgi?id=1265282 * https://bugzilla.suse.com/show_bug.cgi?id=1265283 * https://bugzilla.suse.com/show_bug.cgi?id=1265284 * https://bugzilla.suse.com/show_bug.cgi?id=1265285 * https://bugzilla.suse.com/show_bug.cgi?id=1265286 * https://bugzilla.suse.com/show_bug.cgi?id=1265287 * https://bugzilla.suse.com/show_bug.cgi?id=1265288 * https://bugzilla.suse.com/show_bug.cgi?id=1265289 * https://bugzilla.suse.com/show_bug.cgi?id=1265290 * https://bugzilla.suse.com/show_bug.cgi?id=1265319 * https://bugzilla.suse.com/show_bug.cgi?id=1265358 * https://bugzilla.suse.com/show_bug.cgi?id=1265975 * https://bugzilla.suse.com/show_bug.cgi?id=1266012 * https://bugzilla.suse.com/show_bug.cgi?id=1266556 * https://bugzilla.suse.com/show_bug.cgi?id=1266600 * https://bugzilla.suse.com/show_bug.cgi?id=1266608 * https://bugzilla.suse.com/show_bug.cgi?id=1267153 * https://bugzilla.suse.com/show_bug.cgi?id=1268381 * https://jira.suse.com/browse/MSQA-1056 * https://jira.suse.com/browse/PED-14816 * https://jira.suse.com/browse/SUMA-320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 16:35:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 16:35:39 -0000 Subject: SUSE-SU-2026:2777-1: moderate: Security update for cryptsetup, s390-tools Message-ID: <178335573944.4636.9585972212228823533@4d746be3175e> # Security update for cryptsetup, s390-tools Announcement ID: SUSE-SU-2026:2777-1 Release Date: 2026-07-06T08:57:17Z Rating: moderate References: * bsc#1241612 * bsc#1259314 * bsc#1261813 * bsc#1270185 * jsc#PED-14586 * jsc#PED-15860 * jsc#PED-15889 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability, contains three features and has three security fixes can now be installed. ## Description: This update for cryptsetup, s390-tools fixes the following issue Security fixes: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270185). Changes for s390-tools: * Upgrade s390-tools to version 2.41.0 (jsc#PED-15860) * Automatically set appropriate MTU for HSCI (bsc#1259314) * Changes of existing tools: * chreipl: Make --bootparms work for ECKD re-IPL * cpacfstats: Add 'unauthorized' state to CPU-MF counters * cpictl: Detect RHCOS using VARIANT_ID * hsci: Automatically set appropriate MTU for HSCI * libutil: Add util_readlink() and util_readlinkat() helpers * libutil: Add util_startswith() to util_str * libutil: Add utility parsing functions * lschp: Add support for structured output (--format) * lsreipl: Suppress 'clear' output if not supported * pvimg: Add '\--format text' support to 'pvimg info' * pvimg: Add '\--print-schema ' option to 'pvimg info' * pvimg: Add '\--show-secrets' flag to 'pvimg info' * pvimg: Provide improved JSON output to 'pvimg info --format json' * pvinfo: Improve User experience on non-SE enabled systems * zipl/ngdump: Ensure ext4 file system is used on dump partition * zkey: Add support for integrity protected disks using HMAC keys * Bug Fixes: * cpumf/pai: Handle different size of perf_event_attr * lscss: Fix memory leak * zipl: Fix dump job on tape devices \--- s390-tools 2.40 includes --- * Add new tools / libraries: * Add project-wide .clang-tidy configuration * libutil: Introduce util_time for time related functionality * libutil: Introduce zsh/bash autocompletion tooling based on util_opt * pvinfo: Tool to display Secure Execution system information * pvverify: Tool to verify host-key documents * Changes of existing tools: * cpumf: Implement zsh and bash autocompletion * dasdfmt: Implement zsh and bash autocompletion * dbginfo.sh: Add NetworkManager and netplan * dbginfo.sh: Add kvm_stat * dbginfo.sh: Adding stp time information * dbginfo.sh: Simplify procfs collection * hyptop: Add physical information row * hyptop: Calculate sample time delta for physical partition * hyptop: Replace long option names using _ with - for consistency For example: --cpu_types > \--cpu-types (Options with _ are still supported for backward compatibility) * libekmfweb: Add function to validate a certificate against the identity key * netboot: Add longer kernel command lines support * udev/rules.d: Make virtio-blk devices non-rotational * udev/rules.d: Set default io scheduler to 'none' for virtio-blk * ziomon: Add support to sample device symlinks (/dev/disk/...) * ziorep_config: Add fcp-lun details to -M option output * ziorep_config: Add port_id and failed attributes to -A option output * netboot: Install on non-s390 architectures * Bug Fixes: * lib(ekmfweb|kmipclient): Use ln without -r * s390-tools: Fix various compilation issues with musl libc * zipl/boot: Fix unused loadparm when SCLP line-mode console is absent \--- s390-tools 2.39 includes --- * Changes of existing tools: * chpstat: Add options to select IEC units for scaling (SI units are default) * chzdev: Introduce --no-module-load option * cpi: Disable CPI for SEL guests by default * dbginfo.sh: Enhance logging on timeout triggered * iucvterm: Install symlink for lsiucvallow.8 man page * lshwc: Add command line flag to specify individual counters * lspai: Add command line flag for delta values * lspai: Add command line flag for short counter names * lspai: Add command line flag to specify individual counters * lspai: Add command line flags for all cpus * lspai: Add command line flags for hexadecimal output * man: Use CR for constant width font * pvimg: Add '\--image-key' option * zdev: Allow dynamic control of module load * zipl/boot: Fix EBCDIC code page 500 conversion and decrease size by 200 bytes * zipl: Add support of heterogeneous mirrors (remove technical limitations on mirrored targets, thus allowing mirrored devices consist of partitions at different offsets on disks of different types and geometry). * zkey: Add support for generating and importing exportable secure keys * Bug Fixes: * chpstat: Fix scaling of DPU utilization calculation * zdev/dracut: Prevent loading of unused kernel modules * zdev: Fix double device configuration on DPM systems * zdev: Fix double device configuration with rd.dasd * zipl_helper.device-mapper: Fix segfault in an error path \--- s390-tools 2.38 includes --- * Add new tools * udev: New rule to set newly hotplugged CPUs online * zmemtopo: Display memory topology information * zpwr: Display power readings of a partition and CPC * Removed tools / features * check_hostkeydoc: Remove installation target * scsi_logging_level: Delete SCSI logging script (available in sg3_utils) * zdump: Drop build_arch for s390 DASD dumps * zdump: Drop non-extended multi-volume DASD dump support * zdump: Drop support of 32-bit dump architecture * zdump: Drop support of non-extended single volume DASD dumpers * zdump: Drop support of obsolete dumps and dumpers * Changes of existing tools / libraries * Various man-pages fixes * check_hostkeydoc: Add deprecation warning * check_hostkeydoc: Move to scripts directory * cpuplugd: Allow cpu hotplugging on systems without polarization * dbginfo.sh: Add Ubuntu snap tool * dbginfo.sh: Add missing config data and logs * dbginfo.sh: Reworking the container section * dbginfo.sh: Update for network commands * dbginfo.sh: Updating info for disks and lvm * libutil: Add machine type definition for machines 9175 and 9176 * lscpumf: Add support for IBM z17 counter sets * lshwc: Add command line flag for run time * lshwc: Add flags to display counter values in hex * lshwc: Add output '\--format' option * lshwc: Add support for delta counter value display * lspai: Add output '\--format' option * lsreipl: Add secure boot state to output * lswhc: Add short names to lshwc output * pv_tools: Add Bash and Zsh completions * pvapconfig: Add '\--unbind' option * pvimg/boot: Print error messages from stage3a bootloader * pvimg: Add support for CCK update * pvsecret: Add support for CCK update * pvsecret: Allow retrieving secrets by index; warn for duplicated entries * pvsecret: Deny adding secrets with duplicated secret IDs * zdev: Add support for virtio devices * zipl: Enhance mirror support * zipl: Implement '\--dry-run' option for all dump jobs * zipl_helper.device-mapper: Support mirrors over NVMe devices * zkey/dracut: Add a dracut config file for zkey * zkey/initramfs: Update initramfs hook to correct drivers and include zkey plugins * zkey: Add support for converting a clear-key LUKS2 volume to use a secure key * Bug Fixes * chpstat: Add missing CMG 5 data fields * chpstat: Fix DPU utilization calculation * libutil/util_file: Handle over-read in util_file_read_fd() * pvattest: Fix successful 'check' evaluation * pvsecret: Fix some edge cases for plaintext keys * zipl_helper.device-mapper: Fix imprecise is_device_mapper() predicate * zkey: Fix EP11 secure key reencipher function * zpcictl: Fix command line parsing for invalid options * Amended the .spec file * "Installing" all shipped rules from etc/udev/rules.d to /usr/lib/udev/rules.d * BuildRequires: cryptsetup-devel > 2.8.2 * Updated the code for IBM z17 machine type 9176: * read_values.c * cputype * Renamed cputype.1 to cputype.8 and amended * Amended read_values.8 * "Improved" the read_values.c: * Added functionalities for '-a' and '-L attributes' * Removed legacy suse_version and sle_version conditionals, standardizing on UsrMerge paths. * Reworked and combined all s390-tools patches (jsc#PED-14586) * Added new combined and reworked patches * Removed obsolete patches * Applied patches (bsc#1261813) * Replace sort_field option with sort * hyptop opts Fix long command line option abbreviations * Removed obsolete patch * Re-vendor-ed vendor.tar.zst Changes for cryptsetup: * Update to 2.8.4: (jsc#PED-15889) * Fix integritysetup resize (grow) of the device if integrity bitmap mode is used. Increasing the integrity device in bitmap mode did not work as integritysetup incorrectly used journal settings that were not applicable. * Fix device size status reports in cryptsetup and integritysetup. If the device uses a sector size larger than 512 bytes, the newly reported byte sizes (introduced in 2.8.0) in the status report were incorrectly displayed. * BITLK: Fix unlocking BitLocker device with recovery passphrase. If the recovery passphrase was present in the first keyslot, the device failed to unlock. This bug was introduced in 2.8.2 with Clear Key support. * Update to 2.8.3: * Stable bug-fix release with minor extensions. * Update to 2.8.2: * BITLK: Fix for BitLocker metadata validation on big-endian systems. * Update to 2.8.1: * Fix status and deactivation of TCRYPT (VeraCrypt compatible) devices that use chained ciphers. * Fix unlocking BITLK (BitLocker compatible) devices with multibyte UTF8 characters in the passphrase. * Do not allow activation of the LUKS2 device if the used keyslot is not encrypted (it uses a null cipher). * Such a configuration cannot be created by cryptsetup, but can be crafted outside of it. * Null cipher is sometimes used to create an empty container for later reencryption. * Only an empty passphrase can activate such a container (the same as in LUKS1). * Do not silently decrease PBKDF parallel cost (threads) if set by an option. * The maximum parallel cost is limited to 4 threads. * Fixes to configuration and installation scripts. * Meson and autoconf tools now properly support --prefix option for temporary directory installation. * Multiple fixes and cleanups to config.h for compatibility between Meson and autoconf. * Fix the luks2-external-tokens-path Meson option to work the same as in autoconf. * Fix Meson install for tool binaries, install fvault2Open man page and include test/fuzz/meson.build in release. * Major update to manual pages. * Try to explain the PBKDF hardcoded limits. * Add a better explanation for automatic integrity tag recalculation. * Mention crypt/verity/integritytab. * Remove or reformulate some misleading warnings present only with old and no longer supported kernels. * Clarify that some commands do not wipe data and unify OPAL reset wording. * Clarify the --label option. * There are also many other grammar and stylistic fixes to unify the man-page style. * Fixes for false-positive and annoying (optional) warnings added in recent compilers. * Update to 2.8.0: * Full release notes in: * https://cdn.kernel.org/pub/linux/utils/cryptsetup/v2.8/v2.8.0-ReleaseNotes * Introduce support for inline mode (use HW sectors with additional hardware metadata space). * Finalize use of keyslot context API. * Make all keyslot context types fully self-contained. * Add --key-description and --new-key-description cryptsetup options. * Support more precise keyslot selection in reencryption initialization. * Allow reencryption to resume using token and volume keys. * Cryptsetup repair command now tries to check LUKS keyslot areas for corruption. * Opal2 SED: PSID keyfile is now expected to be 32 alphanumeric characters. * Opal2: Avoid the Erase method and use Secure Erase for locking range. * Opal2: Fix some error description (in debug only). * Opal2: Do not allow deferred deactivation. * Allow --reduce-device-size and --device-size combination for reencryption (encrypt) action. * Fix the userspace storage backend to support kernel "capi:" cipher specification format. * Disallow conversion from LUKS2 to LUKS1 if kernel "capi:" cipher specification is used. * Explicitly disallow kernel "capi:" cipher specification format for LUKS2 keyslot encryption. * Do not allow conversion of LUKS2 to LUKS1 if an unbound keyslot is present. * cryptsetup: Adjust the XTS key size for kernel "capi:" cipher specification. * Remove keyslot warning about possible failure due to low memory. * Do not limit Argon2 KDF memory cost on systems with more than 4GB of available memory. * Properly report out of memory error for cryptographic backends implementing Argon2. * Avoid KDF2 memory cost overflow on 32-bit platforms. * Do not use page size as a fallback for device block size. * veritysetup: Check hash device size in advance. * Print a better error message for unsupported LUKS2 AEAD device resize. * Optimize LUKS2 metadata writes. * veritysetup: support --error-as-corruption option. * Report all sizes in status and dump command output in the correct units. * Add --integrity-key-size option to cryptsetup. * Support trusted; encrypted keyrings for plain devices. * Support plain format resize with a keyring key. * TCRYPT: Clear mapping of system-encrypted partitions. * TCRYPT: Print all information from the decrypted metadata header in the tcryptDump command. * Always lock the volume key structure in memory. * Do not run direct-io read check on block devices. * Fix a possible segfault in deferred deactivation. * Exclude cipher allocation time from the cryptsetup benchmark. * Add Mbed-TLS optional crypto backend. * Fix the wrong preprocessor use of #ifdef for config.h processed by Meson. * Reorganize license files. The license text files are now in docs/licenses. The COPYING file in the root directory is the default license. * Remove cc-by-sa-4.0.txt as already shipped now in docs/licenses and named as COPYING.CC-BY-SA-4.0. * Libcryptsetup API extensions. The libcryptsetup API is backward compatible with all existing symbols. Due to the self-contained memory allocation, these symbols have the new version: * crypt_keyslot_context_init_by_passphrase; * crypt_keyslot_context_init_by_keyfile; * crypt_keyslot_context_init_by_token; * crypt_keyslot_context_init_by_volume_key; * crypt_keyslot_context_init_by_signed_key; * crypt_keyslot_context_init_by_keyring; * crypt_keyslot_context_init_by_vk_in_keyring; * New symbols: * crypt_format_inline * crypt_get_old_volume_key_size * crypt_reencrypt_init_by_keyslot_context * crypt_safe_memcpy * New defines: * CRYPT_ACTIVATE_HIGH_PRIORITY * CRYPT_ACTIVATE_ERROR_AS_CORRUPTION * CRYPT_ACTIVATE_INLINE_MODE * CRYPT_REENCRYPT_CREATE_NEW_DIGEST * New requirement flag: * CRYPT_REQUIREMENT_INLINE_HW_TAGS * Add a dependency on device-mapper to libcryptsetup12 to install the required device-mapper udev rules. (bsc#1241612) * Update to 2.7.5: * Fix possible online reencryption data corruption (only in 2.7.x). In some situations (initializing a suspended device-mapper device), cryptsetup disabled direct-io device access. This caused unsafe online reencryption operations that could lead to data corruption. The code now adds strict checks (and aborts the operation) and changes direct-io detection code to prevent data corruption. * Fix a clang compilation error in SSH token plugin. As clang linker treats missing symbols as errors, the linker phase for the SSH token failed as the optional cryptsetup_token_buffer_free was not defined. * Fix crypto backend initialization in crypt_format_luks2_opal API call. * Update to 2.7.4: * Detect device busy failure for device-mapper table-referenced devices. * Fix shared activation for dm-verity devices. * Add --shared option for veritysetup open action. * Do not use exclusive flag for the allocated backing loop files. * Fixes for problems found by static analyzers and Valgrind. * Fixes to tests and CI scripts. * Use fdupes to link identical man pages. * Update to 2.7.3: * Do not allow formatting LUKS2 with Opal SED (hardware encryption) if the reported logical sector size for the block device and Opal encryption logical block differs. * Fixes to wiping LUKS2 headers after Opal locking area erase. * Mention the need for possible PSID revert before Opal format for some drives (man page). * Fix Bitlocker-compatible code to ignore newly seen metadata entries. * Fix interactive query retry if LUKS2 unbound keyslot is present. * Detect unsupported zoned devices for LUKS header devices. * Allow "capi" cipher format for benchmark command and fix parsing of plain IV in "capi" format. * Add support for HCTR2 encryption mode. * Source code now uses SPDX license identifiers instead of full license preambles. * Fix missing includes for cryptographic backend that could cause compilation errors for some systems. * Fix tests to work correctly in FIPS mode with recent OpenSSL 3.2. * Fix various (mostly false positive) issues detected by Coverity. * License: Replace legacy 'AND SUSE-GPL-2.0-with-openssl-exception' with 'WITH cryptsetup-OpenSSL-exception' (the official SPDX exception). * update to 2.7.2: * Fix activation of OPAL-only encrypted LUKS device with tokens * Fix formatting of OPAL devices with 4096-byte sector size * Fix incorrect OPAL locking range alignment calculation if used over an unaligned device partition. * Do not check the passphrase quality for OPAL Admin PIN, as this passphrase already exists. * Update license for FAQ document to CC BY-SA 4.0. NOTE: Please note that with OPAL-only (--hw-opal-only) encryption, the configured OPAL administrator PIN (passphrase) allows unlocking all configured locking ranges without LUKS keyslot decryption (without knowledge of LUKS passphrase). Because of many observed problems with compatibility, cryptsetup currently DOES NOT use OPAL single-user mode, which would allow such decoupling of OPAL admin PIN access. * Update to 2.7.1: * Fix interrupted LUKS1 decryption resume. With the replacement of the cryptsetup-reencrypt tool by the cryptsetup reencrypt command, resuming the interrupted LUKS1 decryption operation could fail. LUKS2 was not affected. * Allow --link-vk-to-keyring with --test-passphrase option. This option allows uploading the volume key in a user-specified kernel keyring without activating the device. * Fix crash when --active-name was used in decryption initialization. * Updates and changes to man pages, including indentation, sorting options alphabetically, fixing mistakes in crypt_set_keyring_to_link, and fixing some typos. * Fix compilation with libargon2 when --disable-internal-argon2 was used. * Do not require installed argon2.h header and never compile internal libargon2 code if the crypto library directly supports Argon2. * Fixes to regression tests to support older Linux distributions. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2777=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cryptsetup-2.8.4-150700.6.4.4 * cryptsetup-debuginfo-2.8.4-150700.6.4.4 * libcryptsetup-devel-2.8.4-150700.6.4.4 * cryptsetup-ssh-2.8.4-150700.6.4.4 * libcryptsetup12-2.8.4-150700.6.4.4 * cryptsetup-debugsource-2.8.4-150700.6.4.4 * libcryptsetup12-debuginfo-2.8.4-150700.6.4.4 * cryptsetup-ssh-debuginfo-2.8.4-150700.6.4.4 * Basesystem Module 15-SP7 (s390x x86_64) * s390-tools-2.41.0-150700.4.26.2 * Basesystem Module 15-SP7 (noarch) * s390-tools-genprotimg-data-2.41.0-150700.4.26.2 * cryptsetup-doc-2.8.4-150700.6.4.4 * cryptsetup-lang-2.8.4-150700.6.4.4 * Basesystem Module 15-SP7 (s390x) * s390-tools-debuginfo-2.41.0-150700.4.26.2 * s390-tools-debugsource-2.41.0-150700.4.26.2 * libekmfweb1-2.41.0-150700.4.26.2 * s390-tools-zdsfs-debuginfo-2.41.0-150700.4.26.2 * libkmipclient1-2.41.0-150700.4.26.2 * osasnmpd-2.41.0-150700.4.26.2 * libkmipclient1-debuginfo-2.41.0-150700.4.26.2 * libekmfweb1-devel-2.41.0-150700.4.26.2 * s390-tools-chreipl-fcp-mpath-2.41.0-150700.4.26.2 * s390-tools-hmcdrvfs-debuginfo-2.41.0-150700.4.26.2 * s390-tools-hmcdrvfs-2.41.0-150700.4.26.2 * osasnmpd-debuginfo-2.41.0-150700.4.26.2 * libekmfweb1-debuginfo-2.41.0-150700.4.26.2 * s390-tools-zdsfs-2.41.0-150700.4.26.2 * Basesystem Module 15-SP7 (x86_64) * libcryptsetup12-32bit-debuginfo-2.8.4-150700.6.4.4 * libcryptsetup12-32bit-2.8.4-150700.6.4.4 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1241612 * https://bugzilla.suse.com/show_bug.cgi?id=1259314 * https://bugzilla.suse.com/show_bug.cgi?id=1261813 * https://bugzilla.suse.com/show_bug.cgi?id=1270185 * https://jira.suse.com/browse/PED-14586 * https://jira.suse.com/browse/PED-15860 * https://jira.suse.com/browse/PED-15889 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 20:30:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 20:30:06 -0000 Subject: SUSE-SU-2026:2781-1: moderate: Security update for postfix Message-ID: <178336980654.599.4955389659829818691@2afce7b7fe24> # Security update for postfix Announcement ID: SUSE-SU-2026:2781-1 Release Date: 2026-07-06T14:12:18Z Rating: moderate References: * bsc#1264062 Cross-References: * CVE-2026-43964 CVSS scores: * CVE-2026-43964 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43964 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Legacy Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for postfix fixes the following issue * CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-2781=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2781=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2781=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2781=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postfix-bdb-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-debuginfo-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-3.8.4-150600.3.6.1 * postfix-bdb-debugsource-3.8.4-150600.3.6.1 * postfix-bdb-debuginfo-3.8.4-150600.3.6.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postfix-mysql-debuginfo-3.8.4-150600.3.6.1 * postfix-mysql-3.8.4-150600.3.6.1 * postfix-debugsource-3.8.4-150600.3.6.1 * postfix-debuginfo-3.8.4-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postfix-ldap-debuginfo-3.8.4-150600.3.6.1 * postfix-mysql-debuginfo-3.8.4-150600.3.6.1 * postfix-postgresql-3.8.4-150600.3.6.1 * postfix-debugsource-3.8.4-150600.3.6.1 * postfix-bdb-3.8.4-150600.3.6.1 * postfix-debuginfo-3.8.4-150600.3.6.1 * postfix-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-debuginfo-3.8.4-150600.3.6.1 * postfix-bdb-lmdb-3.8.4-150600.3.6.1 * postfix-ldap-3.8.4-150600.3.6.1 * postfix-bdb-debugsource-3.8.4-150600.3.6.1 * postfix-mysql-3.8.4-150600.3.6.1 * postfix-postgresql-debuginfo-3.8.4-150600.3.6.1 * postfix-bdb-debuginfo-3.8.4-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * postfix-devel-3.8.4-150600.3.6.1 * postfix-doc-3.8.4-150600.3.6.1 * Basesystem Module 15-SP7 (noarch) * postfix-devel-3.8.4-150600.3.6.1 * postfix-doc-3.8.4-150600.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postfix-ldap-debuginfo-3.8.4-150600.3.6.1 * postfix-ldap-3.8.4-150600.3.6.1 * postfix-debuginfo-3.8.4-150600.3.6.1 * postfix-3.8.4-150600.3.6.1 * postfix-debugsource-3.8.4-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43964.html * https://bugzilla.suse.com/show_bug.cgi?id=1264062 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 20:30:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 20:30:12 -0000 Subject: SUSE-SU-2026:2780-1: moderate: Security update for postfix Message-ID: <178336981275.599.10878884332002877151@2afce7b7fe24> # Security update for postfix Announcement ID: SUSE-SU-2026:2780-1 Release Date: 2026-07-06T14:11:50Z Rating: moderate References: * bsc#1264062 Cross-References: * CVE-2026-43964 CVSS scores: * CVE-2026-43964 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43964 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for postfix fixes the following issue * CVE-2026-43964: buffer overread and process crash via an enhanced status code that lacks text after the third number (bsc#1264062). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2780=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * postfix-doc-3.2.10-3.33.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * postfix-mysql-3.2.10-3.33.1 * postfix-devel-3.2.10-3.33.1 * postfix-debuginfo-3.2.10-3.33.1 * postfix-debugsource-3.2.10-3.33.1 * postfix-3.2.10-3.33.1 * postfix-mysql-debuginfo-3.2.10-3.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43964.html * https://bugzilla.suse.com/show_bug.cgi?id=1264062 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 6 20:30:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 06 Jul 2026 20:30:26 -0000 Subject: SUSE-SU-2026:2779-1: important: Security update for bind Message-ID: <178336982638.599.15221524044118680041@2afce7b7fe24> # Security update for bind Announcement ID: SUSE-SU-2026:2779-1 Release Date: 2026-07-06T14:07:45Z Rating: important References: * bsc#1265591 * bsc#1265592 * bsc#1265594 Cross-References: * CVE-2026-3039 * CVE-2026-3592 * CVE-2026-5946 CVSS scores: * CVE-2026-3039 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3039 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3592 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-3592 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5946 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2026-3039: BIND 9 server memory exhaustion during GSS-API TKEY negotiation (bsc#1265591). * CVE-2026-3592: Amplification vulnerabilities via self-pointed glue records (bsc#1265592). * CVE-2026-5946: Invalid handling of CLASS != IN (bsc#1265594). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2779=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2779=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2779=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2779=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libirs1601-debuginfo-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * bind-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * bind-devel-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * bind-utils-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libbind9-1600-9.16.6-150300.22.59.1 * libbind9-1600-debuginfo-9.16.6-150300.22.59.1 * libns1604-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * libisccc1600-debuginfo-9.16.6-150300.22.59.1 * libisccc1600-9.16.6-150300.22.59.1 * bind-utils-debuginfo-9.16.6-150300.22.59.1 * bind-chrootenv-9.16.6-150300.22.59.1 * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libns1604-debuginfo-9.16.6-150300.22.59.1 * openSUSE Leap 15.3 (noarch) * python3-bind-9.16.6-150300.22.59.1 * bind-doc-9.16.6-150300.22.59.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libisccfg1600-9.16.6-150300.22.59.1 * libisc1606-debuginfo-9.16.6-150300.22.59.1 * libisccfg1600-debuginfo-9.16.6-150300.22.59.1 * libirs1601-debuginfo-9.16.6-150300.22.59.1 * bind-debuginfo-9.16.6-150300.22.59.1 * libirs-devel-9.16.6-150300.22.59.1 * libdns1605-9.16.6-150300.22.59.1 * libisc1606-9.16.6-150300.22.59.1 * libdns1605-debuginfo-9.16.6-150300.22.59.1 * bind-debugsource-9.16.6-150300.22.59.1 * libirs1601-9.16.6-150300.22.59.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3039.html * https://www.suse.com/security/cve/CVE-2026-3592.html * https://www.suse.com/security/cve/CVE-2026-5946.html * https://bugzilla.suse.com/show_bug.cgi?id=1265591 * https://bugzilla.suse.com/show_bug.cgi?id=1265592 * https://bugzilla.suse.com/show_bug.cgi?id=1265594 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 7 08:30:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 07 Jul 2026 08:30:11 -0000 Subject: SUSE-SU-2026:2782-1: important: Security update for perl-Cpanel-JSON-XS Message-ID: <178341301168.10238.14016029745842323762@63abed19989d> # Security update for perl-Cpanel-JSON-XS Announcement ID: SUSE-SU-2026:2782-1 Release Date: 2026-07-06T18:01:58Z Rating: important References: * bsc#1267546 * bsc#1267547 Cross-References: * CVE-2026-9334 * CVE-2026-9516 CVSS scores: * CVE-2026-9334 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-9334 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9334 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9516 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9516 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-Cpanel-JSON-XS fixes the following issues * CVE-2026-9334: type confusion via duplicate object keys when `dupkeys_as_arrayref` is enabled (bsc#1267546). * CVE-2026-9516: denial of service via UTF-8 BOM prefixed input when a decode filter callback throws (bsc#1267547). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2782=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-Cpanel-JSON-XS-debuginfo-4.380.0-150700.3.6.1 * perl-Cpanel-JSON-XS-4.380.0-150700.3.6.1 * perl-Cpanel-JSON-XS-debugsource-4.380.0-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9334.html * https://www.suse.com/security/cve/CVE-2026-9516.html * https://bugzilla.suse.com/show_bug.cgi?id=1267546 * https://bugzilla.suse.com/show_bug.cgi?id=1267547 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 08:30:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 08:30:13 -0000 Subject: SUSE-SU-2026:2783-1: important: Security update for kubevirt-1.6 Message-ID: <178349941309.273.4294195258653263524@5ed4f61072e9> # Security update for kubevirt-1.6 Announcement ID: SUSE-SU-2026:2783-1 Release Date: 2026-07-07T15:05:10Z Rating: important References: * bsc#1256434 * bsc#1262265 * bsc#1266733 Cross-References: * CVE-2025-14525 * CVE-2026-35469 * CVE-2026-9804 CVSS scores: * CVE-2025-14525 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-14525 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-14525 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9804 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for kubevirt-1.6 fixes the following issues: * CVE-2026-9804: Symlink escape in the VMExport dir handler let an attacker controlling an exported PVC read sensitive files (TLS keys, tokens, service- account creds) from the exporter pod. (bsc#1266733) * CVE-2025-14525: A VM reporting many guest-internal interfaces via the guest agent could flood VMI status and fill etcd (denial of service). Caps reported interfaces at 10. (bsc#1256434) * CVE-2026-35469: resource-exhaustion in the SPDY/3 protocol implementation of github.com/moby/spdystream. (GHSA-pc3f-x583-g7j2,bsc#1262265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2783=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-1.6-virtctl-debuginfo-1.6.6-150700.15.10.1 * kubevirt-1.6-virtctl-1.6.6-150700.15.10.1 * kubevirt-1.6-manifests-1.6.6-150700.15.10.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14525.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-9804.html * https://bugzilla.suse.com/show_bug.cgi?id=1256434 * https://bugzilla.suse.com/show_bug.cgi?id=1262265 * https://bugzilla.suse.com/show_bug.cgi?id=1266733 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 12:31:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 12:31:15 -0000 Subject: SUSE-SU-2026:22523-1: moderate: Security update for glibc Message-ID: <178351387581.407.471260724287435956@530c474df1e7> # Security update for glibc Announcement ID: SUSE-SU-2026:22523-1 Release Date: 2026-07-06T13:14:21Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-784=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * glibc-debugsource-2.38-14.1 * glibc-locale-base-2.38-14.1 * glibc-devel-2.38-14.1 * glibc-debuginfo-2.38-14.1 * glibc-locale-2.38-14.1 * glibc-locale-base-debuginfo-2.38-14.1 * glibc-2.38-14.1 * glibc-devel-debuginfo-2.38-14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:32:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:32:18 -0000 Subject: SUSE-SU-2026:22522-1: important: Security update for the Linux Kernel Message-ID: <178352833899.452.4099111859093689802@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22522-1 Release Date: 2026-07-06T13:11:38Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-502=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * kernel-devel-rt-6.4.0-49.1 * kernel-source-rt-6.4.0-49.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-rt-livepatch-6.4.0-49.1 * kernel-rt-debuginfo-6.4.0-49.1 * kernel-rt-debugsource-6.4.0-49.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-rt-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:34:26 -0000 Subject: SUSE-SU-2026:22521-1: important: Security update for the Linux Kernel Message-ID: <178352846676.452.2671187793119342234@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22521-1 Release Date: 2026-07-06T13:11:37Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-501=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-kvmsmall-debugsource-6.4.0-49.1 * kernel-kvmsmall-debuginfo-6.4.0-49.1 * SUSE Linux Micro 6.0 (noarch) * kernel-source-6.4.0-49.1 * kernel-macros-6.4.0-49.1 * kernel-devel-6.4.0-49.1 * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-default-livepatch-6.4.0-49.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kernel-default-debuginfo-6.4.0-49.1 * kernel-default-debugsource-6.4.0-49.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-kvmsmall-6.4.0-49.1 * SUSE Linux Micro 6.0 (aarch64 nosrc s390x x86_64) * kernel-default-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:34:41 -0000 Subject: SUSE-SU-2026:22518-1: important: Security update for kernel-livepatch-MICRO-6-0_Update_26 Message-ID: <178352848181.452.14854858715459270200@57e59d802799> # Security update for kernel-livepatch-MICRO-6-0_Update_26 Announcement ID: SUSE-SU-2026:22518-1 Release Date: 2026-07-06T09:28:38Z Rating: important References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-500=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-1-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-default-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:34:45 -0000 Subject: SUSE-SU-2026:22517-1: moderate: Security update for kernel-livepatch-MICRO-6-0-RT_Update_26 Message-ID: <178352848588.452.18100438338311413372@57e59d802799> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_26 Announcement ID: SUSE-SU-2026:22517-1 Release Date: 2026-07-06T09:18:54Z Rating: moderate References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_26 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 26 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-503=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-1-1.1 * kernel-livepatch-6_4_0-49-rt-1-1.1 * kernel-livepatch-6_4_0-49-rt-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:34:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:34:53 -0000 Subject: SUSE-SU-2026:22516-1: important: Security update for podman Message-ID: <178352849373.452.15249578306775144294@57e59d802799> # Security update for podman Announcement ID: SUSE-SU-2026:22516-1 Release Date: 2026-07-03T12:53:16Z Rating: important References: * bsc#1262856 * bsc#1266125 Cross-References: * CVE-2024-6104 * CVE-2025-22869 * CVE-2025-27144 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-52881 * CVE-2025-6032 * CVE-2025-9566 * CVE-2026-34986 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2024-6104 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2024-6104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-27144 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-27144 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-52881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-52881 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-52881 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-52881 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-6032 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-6032 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-9566 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-9566 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2025-9566 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for podman fixes the following issues * CVE-2026-34986: github.com/go-jose/go-jose/v4,github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262856). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266125). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266125). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266125). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266125). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-779=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * podman-docker-4.9.5-12.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * podman-4.9.5-12.1 * podman-remote-debuginfo-4.9.5-12.1 * podmansh-4.9.5-12.1 * podman-remote-4.9.5-12.1 * podman-debuginfo-4.9.5-12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-6104.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2025-27144.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-52881.html * https://www.suse.com/security/cve/CVE-2025-6032.html * https://www.suse.com/security/cve/CVE-2025-9566.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1262856 * https://bugzilla.suse.com/show_bug.cgi?id=1266125 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:35:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:35:00 -0000 Subject: SUSE-SU-2026:22515-1: important: Security update for haproxy Message-ID: <178352850059.452.16797612610092751581@57e59d802799> # Security update for haproxy Announcement ID: SUSE-SU-2026:22515-1 Release Date: 2026-07-03T12:51:57Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-781=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * haproxy-debugsource-2.8.11+git0.01c1056a4-4.1 * haproxy-debuginfo-2.8.11+git0.01c1056a4-4.1 * haproxy-2.8.11+git0.01c1056a4-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:35:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:35:06 -0000 Subject: SUSE-SU-2026:22514-1: moderate: Security update for libslirp Message-ID: <178352850628.452.8816337090910860710@57e59d802799> # Security update for libslirp Announcement ID: SUSE-SU-2026:22514-1 Release Date: 2026-07-03T12:51:57Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issue * CVE-2026-9539: TCP URG out of bounds heap read information leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-780=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libslirp-debugsource-4.7.0+44-5.1 * libslirp0-debuginfo-4.7.0+44-5.1 * libslirp0-4.7.0+44-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:35:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:35:16 -0000 Subject: SUSE-SU-2026:22513-1: important: Security update for docker Message-ID: <178352851640.452.3529422855784552601@57e59d802799> # Security update for docker Announcement ID: SUSE-SU-2026:22513-1 Release Date: 2026-07-02T18:48:26Z Rating: important References: * bsc#1262346 * bsc#1265782 * bsc#1266625 * bsc#1267827 Cross-References: * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-39984 * CVE-2026-41567 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39984 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-39984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41567 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-41567 ( NVD ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker fixes the following issues * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). * CVE-2026-39984: github.com/sigstore/timestamp-authority/v2/pkg/verification: improper certificate validation can be used to bypass some authorization controls (bsc#1262346). * CVE-2026-41567: arbitrary code execution with full daemon privileges when a user uploads a compressed archive into that container (bsc#1267827). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-778=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * docker-buildx-0.33.0-11.1 * docker-debuginfo-29.4.0_ce-11.1 * docker-29.4.0_ce-11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39984.html * https://www.suse.com/security/cve/CVE-2026-41567.html * https://bugzilla.suse.com/show_bug.cgi?id=1262346 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 * https://bugzilla.suse.com/show_bug.cgi?id=1267827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:37:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:37:30 -0000 Subject: SUSE-SU-2026:22512-1: important: Security update for the Linux Kernel Message-ID: <178352865053.452.16763750934593995719@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22512-1 Release Date: 2026-07-06T13:11:38Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-502=1 ## Package List: * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-rt-devel-debuginfo-6.4.0-49.1 * kernel-rt-devel-6.4.0-49.1 * kernel-rt-debugsource-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-rt-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:39:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:39:39 -0000 Subject: SUSE-SU-2026:22511-1: important: Security update for the Linux Kernel Message-ID: <178352877955.452.4040993381955438337@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:22511-1 Release Date: 2026-07-06T13:11:36Z Rating: important References: * bsc#1255029 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264228 * bsc#1264230 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268237 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43107 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46214 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 89 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-501=1 ## Package List: * SUSE Linux Micro Extras 6.0 (aarch64) * kernel-64kb-debugsource-6.4.0-49.1 * kernel-64kb-devel-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * kernel-obs-build-6.4.0-49.1 * kernel-default-devel-6.4.0-49.1 * kernel-obs-build-debugsource-6.4.0-49.1 * kernel-syms-6.4.0-49.1 * kernel-default-debugsource-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-default-6.4.0-49.1 * kernel-64kb-6.4.0-49.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-default-devel-debuginfo-6.4.0-49.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:39:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:39:48 -0000 Subject: SUSE-SU-2026:2794-1: important: Security update for libXfont2 Message-ID: <178352878821.452.3384015621180339772@57e59d802799> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:2794-1 Release Date: 2026-07-08T08:08:25Z Rating: important References: * bsc#1269018 * bsc#1269019 * bsc#1269020 Cross-References: * CVE-2026-56001 * CVE-2026-56002 * CVE-2026-56003 CVSS scores: * CVE-2026-56001 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56001 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56002 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56002 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56002 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56003 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56003 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56003 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues * CVE-2026-56001: integer overflow in `BitmapScaleBitmaps` can lead to a heap buffer overflow (bsc#1269018). * CVE-2026-56002: insufficient checks in `pcfReadFont` can lead to a heap buffer overflow (bsc#1269019). * CVE-2026-56003: missing bounds check in `ComputeScaledProperties` can lead to a heap buffer overflow (bsc#1269020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2794=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2794=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2794=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2794=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2794=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2794=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2794=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2794=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2794=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2794=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2794=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x) * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le) * libXfont2-2-2.0.3-150000.3.3.1 * libXfont2-devel-2.0.3-150000.3.3.1 * libXfont2-2-debuginfo-2.0.3-150000.3.3.1 * libXfont2-debugsource-2.0.3-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56001.html * https://www.suse.com/security/cve/CVE-2026-56002.html * https://www.suse.com/security/cve/CVE-2026-56003.html * https://bugzilla.suse.com/show_bug.cgi?id=1269018 * https://bugzilla.suse.com/show_bug.cgi?id=1269019 * https://bugzilla.suse.com/show_bug.cgi?id=1269020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:39:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:39:56 -0000 Subject: SUSE-SU-2026:2793-1: important: Security update for libXfont2 Message-ID: <178352879655.452.10427913151427693626@57e59d802799> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:2793-1 Release Date: 2026-07-08T08:06:28Z Rating: important References: * bsc#1269018 * bsc#1269019 * bsc#1269020 Cross-References: * CVE-2026-56001 * CVE-2026-56002 * CVE-2026-56003 CVSS scores: * CVE-2026-56001 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56001 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56002 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56002 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56002 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56003 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56003 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56003 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues * CVE-2026-56001: integer overflow in `BitmapScaleBitmaps` can lead to a heap buffer overflow (bsc#1269018). * CVE-2026-56002: insufficient checks in `pcfReadFont` can lead to a heap buffer overflow (bsc#1269019). * CVE-2026-56003: missing bounds check in `ComputeScaledProperties` can lead to a heap buffer overflow (bsc#1269020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2793=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x) * libXfont2-2-debuginfo-2.0.3-3.3.1 * libXfont2-2-2.0.3-3.3.1 * libXfont2-debugsource-2.0.3-3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56001.html * https://www.suse.com/security/cve/CVE-2026-56002.html * https://www.suse.com/security/cve/CVE-2026-56003.html * https://bugzilla.suse.com/show_bug.cgi?id=1269018 * https://bugzilla.suse.com/show_bug.cgi?id=1269019 * https://bugzilla.suse.com/show_bug.cgi?id=1269020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:02 -0000 Subject: SUSE-SU-2026:2792-1: important: Security update for xorg-x11-server Message-ID: <178352880258.452.2029873800944840086@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2792-1 Release Date: 2026-07-08T07:55:40Z Rating: important References: * bsc#1268893 Cross-References: * CVE-2026-55999 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for xorg-x11-server fixes the following issue * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2792=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2792=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-extra-1.19.6-10.105.1 * xorg-x11-server-debuginfo-1.19.6-10.105.1 * xorg-x11-server-1.19.6-10.105.1 * xorg-x11-server-extra-debuginfo-1.19.6-10.105.1 * xorg-x11-server-debugsource-1.19.6-10.105.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * xorg-x11-server-extra-1.19.6-10.105.1 * xorg-x11-server-debuginfo-1.19.6-10.105.1 * xorg-x11-server-1.19.6-10.105.1 * xorg-x11-server-extra-debuginfo-1.19.6-10.105.1 * xorg-x11-server-debugsource-1.19.6-10.105.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:09 -0000 Subject: SUSE-SU-2026:2791-1: important: Security update for xorg-x11-server Message-ID: <178352880994.452.15196044584126977858@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2791-1 Release Date: 2026-07-08T07:33:14Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2791=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2791=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2791=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2791=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2791=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-source-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-Xvfb-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-Xvfb-21.1.4-150500.7.52.1 * xorg-x11-server-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-sdk-21.1.4-150500.7.52.1 * xorg-x11-server-debugsource-21.1.4-150500.7.52.1 * xorg-x11-server-extra-21.1.4-150500.7.52.1 * xorg-x11-server-extra-debuginfo-21.1.4-150500.7.52.1 * xorg-x11-server-21.1.4-150500.7.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:17 -0000 Subject: SUSE-SU-2026:2789-1: important: Security update for xorg-x11-server Message-ID: <178352881731.452.10430659767519196273@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2789-1 Release Date: 2026-07-08T07:29:10Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2789=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2789=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2789=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2789=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2789=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * xorg-x11-server-source-1.20.3-150400.38.74.1 * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * xorg-x11-server-extra-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-1.20.3-150400.38.74.1 * xorg-x11-server-sdk-1.20.3-150400.38.74.1 * xorg-x11-server-debuginfo-1.20.3-150400.38.74.1 * xorg-x11-server-extra-1.20.3-150400.38.74.1 * xorg-x11-server-debugsource-1.20.3-150400.38.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:25 -0000 Subject: SUSE-SU-2026:2788-1: important: Security update for xorg-x11-server Message-ID: <178352882532.452.3794031818168676670@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2788-1 Release Date: 2026-07-08T07:22:17Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2788=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2788=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debugsource-21.1.15-150700.5.22.1 * xorg-x11-server-sdk-21.1.15-150700.5.22.1 * xorg-x11-server-debuginfo-21.1.15-150700.5.22.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * xorg-x11-server-debugsource-21.1.15-150700.5.22.1 * xorg-x11-server-21.1.15-150700.5.22.1 * xorg-x11-server-Xvfb-debuginfo-21.1.15-150700.5.22.1 * xorg-x11-server-extra-debuginfo-21.1.15-150700.5.22.1 * xorg-x11-server-Xvfb-21.1.15-150700.5.22.1 * xorg-x11-server-debuginfo-21.1.15-150700.5.22.1 * xorg-x11-server-extra-21.1.15-150700.5.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:32 -0000 Subject: SUSE-SU-2026:2787-1: important: Security update for xwayland Message-ID: <178352883218.452.13592141566023439959@57e59d802799> # Security update for xwayland Announcement ID: SUSE-SU-2026:2787-1 Release Date: 2026-07-08T07:19:18Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2787=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * xwayland-24.1.5-150700.3.22.1 * xwayland-debugsource-24.1.5-150700.3.22.1 * xwayland-debuginfo-24.1.5-150700.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:39 -0000 Subject: SUSE-SU-2026:2786-1: important: Security update for xorg-x11-server Message-ID: <178352883906.452.10385785155145884139@57e59d802799> # Security update for xorg-x11-server Announcement ID: SUSE-SU-2026:2786-1 Release Date: 2026-07-08T07:16:51Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for xorg-x11-server fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2786=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2786=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2786=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * xorg-x11-server-sdk-21.1.11-150600.5.31.1 * xorg-x11-server-extra-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-extra-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-debugsource-21.1.11-150600.5.31.1 * xorg-x11-server-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-21.1.11-150600.5.31.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * xorg-x11-server-sdk-21.1.11-150600.5.31.1 * xorg-x11-server-extra-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-extra-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-debugsource-21.1.11-150600.5.31.1 * xorg-x11-server-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-21.1.11-150600.5.31.1 * xorg-x11-server-source-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-21.1.11-150600.5.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * xorg-x11-server-sdk-21.1.11-150600.5.31.1 * xorg-x11-server-extra-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-extra-21.1.11-150600.5.31.1 * xorg-x11-server-debugsource-21.1.11-150600.5.31.1 * xorg-x11-server-debuginfo-21.1.11-150600.5.31.1 * xorg-x11-server-21.1.11-150600.5.31.1 * xorg-x11-server-Xvfb-21.1.11-150600.5.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 16:40:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 16:40:48 -0000 Subject: SUSE-SU-2026:2785-1: moderate: Security update for systemd, systemd-mini Message-ID: <178352884890.452.18174966566126645619@57e59d802799> # Security update for systemd, systemd-mini Announcement ID: SUSE-SU-2026:2785-1 Release Date: 2026-07-08T06:48:14Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.2 * SUSE Linux Enterprise Micro for Rancher 5.2 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for systemd, systemd-mini fixes the following issue Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit eba1930de8 (bsc#1267647). * Import commit 5d46cdd987 (bsc#1261982 bsc#1261983). * Import commit ac1173932c (bsc#1261982). * Import commit c7f3e89374 (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2785=1 * SUSE Linux Enterprise Micro for Rancher 5.2 zypper in -t patch SUSE-SUSE-MicroOS-5.2-2026-2785=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2785=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * systemd-sysvinit-246.16-150300.7.74.1 * systemd-mini-246.16-150300.7.74.1 * udev-mini-246.16-150300.7.74.1 * systemd-portable-246.16-150300.7.74.1 * systemd-mini-devel-246.16-150300.7.74.1 * systemd-coredump-debuginfo-246.16-150300.7.74.1 * systemd-container-246.16-150300.7.74.1 * nss-mymachines-debuginfo-246.16-150300.7.74.1 * udev-mini-debuginfo-246.16-150300.7.74.1 * udev-debuginfo-246.16-150300.7.74.1 * systemd-network-debuginfo-246.16-150300.7.74.1 * systemd-mini-debuginfo-246.16-150300.7.74.1 * nss-systemd-debuginfo-246.16-150300.7.74.1 * libudev1-debuginfo-246.16-150300.7.74.1 * systemd-coredump-246.16-150300.7.74.1 * libsystemd0-mini-246.16-150300.7.74.1 * systemd-devel-246.16-150300.7.74.1 * nss-resolve-246.16-150300.7.74.1 * libudev-devel-246.16-150300.7.74.1 * libsystemd0-mini-debuginfo-246.16-150300.7.74.1 * nss-myhostname-246.16-150300.7.74.1 * systemd-246.16-150300.7.74.1 * libsystemd0-debuginfo-246.16-150300.7.74.1 * systemd-mini-sysvinit-246.16-150300.7.74.1 * systemd-doc-246.16-150300.7.74.1 * systemd-mini-container-246.16-150300.7.74.1 * udev-246.16-150300.7.74.1 * nss-systemd-246.16-150300.7.74.1 * libudev-mini1-246.16-150300.7.74.1 * systemd-network-246.16-150300.7.74.1 * nss-resolve-debuginfo-246.16-150300.7.74.1 * systemd-debuginfo-246.16-150300.7.74.1 * nss-mymachines-246.16-150300.7.74.1 * systemd-journal-remote-246.16-150300.7.74.1 * nss-myhostname-debuginfo-246.16-150300.7.74.1 * libudev-mini-devel-246.16-150300.7.74.1 * systemd-debugsource-246.16-150300.7.74.1 * systemd-mini-container-debuginfo-246.16-150300.7.74.1 * systemd-logger-246.16-150300.7.74.1 * libudev-mini1-debuginfo-246.16-150300.7.74.1 * libsystemd0-246.16-150300.7.74.1 * systemd-journal-remote-debuginfo-246.16-150300.7.74.1 * libudev1-246.16-150300.7.74.1 * systemd-container-debuginfo-246.16-150300.7.74.1 * systemd-mini-debugsource-246.16-150300.7.74.1 * systemd-portable-debuginfo-246.16-150300.7.74.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libsystemd0-64bit-debuginfo-246.16-150300.7.74.1 * libsystemd0-64bit-246.16-150300.7.74.1 * libudev-devel-64bit-246.16-150300.7.74.1 * nss-mymachines-64bit-246.16-150300.7.74.1 * nss-myhostname-64bit-246.16-150300.7.74.1 * nss-mymachines-64bit-debuginfo-246.16-150300.7.74.1 * systemd-64bit-246.16-150300.7.74.1 * nss-myhostname-64bit-debuginfo-246.16-150300.7.74.1 * libudev1-64bit-debuginfo-246.16-150300.7.74.1 * libudev1-64bit-246.16-150300.7.74.1 * systemd-64bit-debuginfo-246.16-150300.7.74.1 * openSUSE Leap 15.3 (x86_64) * libsystemd0-32bit-246.16-150300.7.74.1 * libudev1-32bit-246.16-150300.7.74.1 * libudev-devel-32bit-246.16-150300.7.74.1 * nss-mymachines-32bit-246.16-150300.7.74.1 * nss-myhostname-32bit-246.16-150300.7.74.1 * systemd-32bit-debuginfo-246.16-150300.7.74.1 * libsystemd0-32bit-debuginfo-246.16-150300.7.74.1 * nss-mymachines-32bit-debuginfo-246.16-150300.7.74.1 * systemd-32bit-246.16-150300.7.74.1 * nss-myhostname-32bit-debuginfo-246.16-150300.7.74.1 * libudev1-32bit-debuginfo-246.16-150300.7.74.1 * openSUSE Leap 15.3 (noarch) * systemd-lang-246.16-150300.7.74.1 * SUSE Linux Enterprise Micro 5.2 (aarch64 s390x x86_64) * systemd-sysvinit-246.16-150300.7.74.1 * systemd-debugsource-246.16-150300.7.74.1 * systemd-246.16-150300.7.74.1 * libsystemd0-debuginfo-246.16-150300.7.74.1 * libsystemd0-246.16-150300.7.74.1 * udev-246.16-150300.7.74.1 * systemd-container-246.16-150300.7.74.1 * systemd-journal-remote-debuginfo-246.16-150300.7.74.1 * libudev1-246.16-150300.7.74.1 * udev-debuginfo-246.16-150300.7.74.1 * systemd-container-debuginfo-246.16-150300.7.74.1 * systemd-debuginfo-246.16-150300.7.74.1 * libudev1-debuginfo-246.16-150300.7.74.1 * systemd-journal-remote-246.16-150300.7.74.1 * SUSE Linux Enterprise Micro for Rancher 5.2 (aarch64 s390x x86_64) * systemd-sysvinit-246.16-150300.7.74.1 * systemd-debugsource-246.16-150300.7.74.1 * systemd-246.16-150300.7.74.1 * libsystemd0-debuginfo-246.16-150300.7.74.1 * libsystemd0-246.16-150300.7.74.1 * udev-246.16-150300.7.74.1 * systemd-container-246.16-150300.7.74.1 * systemd-journal-remote-debuginfo-246.16-150300.7.74.1 * libudev1-246.16-150300.7.74.1 * udev-debuginfo-246.16-150300.7.74.1 * systemd-container-debuginfo-246.16-150300.7.74.1 * systemd-debuginfo-246.16-150300.7.74.1 * libudev1-debuginfo-246.16-150300.7.74.1 * systemd-journal-remote-246.16-150300.7.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 20:32:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 20:32:47 -0000 Subject: SUSE-SU-2026:2800-1: important: Security update for the Linux Kernel Message-ID: <178354276740.547.17725689517794649513@530c474df1e7> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2800-1 Release Date: 2026-07-08T14:59:46Z Rating: important References: * bsc#1236743 * bsc#1255029 * bsc#1259764 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262618 * bsc#1262655 * bsc#1263072 * bsc#1263560 * bsc#1263573 * bsc#1263581 * bsc#1263879 * bsc#1263880 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264084 * bsc#1264116 * bsc#1264145 * bsc#1264228 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264449 * bsc#1264484 * bsc#1264562 * bsc#1264612 * bsc#1264734 * bsc#1264748 * bsc#1264814 * bsc#1264974 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266008 * bsc#1266396 * bsc#1266700 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1267228 * bsc#1267365 * bsc#1267369 * bsc#1267381 * bsc#1267427 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267682 * bsc#1267684 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267953 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268049 * bsc#1268159 * bsc#1268237 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269199 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269617 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-15880 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-40216 * CVE-2025-40341 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31450 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31502 * CVE-2026-31647 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43034 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43107 * CVE-2026-43109 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43284 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45848 * CVE-2026-45891 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45985 * CVE-2026-46028 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46120 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46197 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46315 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46330 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-40216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46315 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 105 vulnerabilities, contains three features and has 12 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43053: xfs: close crash window in attr dabtree inactivation (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1264484). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * iommu/s390: allow larger region tables (jsc#PED-15880). * iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). * iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). * iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). * iommu/s390: set appropriate IOTA region type (jsc#PED-15880). * iommu/s390: support cleanup of additional table regions (jsc#PED-15880). * iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). * iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * s390/pci: check for relaxed translation capability (jsc#PED-15880). * s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). * s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). * selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). * selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). * selftests/bpf: Skip tests whose objects were not built (bsc#1269617). * selftests/bpf: Tolerate benchmark build failures (bsc#1269617). * selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). * selftests/bpf: Tolerate missing files during install (bsc#1269617). * selftests/bpf: Tolerate test file compilation failures (bsc#1269617). * serdev: make serdev_bus_type const (stable-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2800=1 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2800=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2800=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-2800=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2800=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2800=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-2800=1 ## Package List: * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.66.1 * reiserfs-kmp-default-6.4.0-150700.53.66.1 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.66.1 * ocfs2-kmp-default-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.66.1 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.66.1 * gfs2-kmp-default-6.4.0-150700.53.66.1 * dlm-kmp-default-6.4.0-150700.53.66.1 * cluster-md-kmp-default-6.4.0-150700.53.66.1 * dlm-kmp-default-debuginfo-6.4.0-150700.53.66.1 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.66.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (noarch) * kernel-macros-6.4.0-150700.53.66.1 * kernel-devel-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-6.4.0-150700.53.66.1 * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * kernel-default-devel-debuginfo-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-devel-6.4.0-150700.53.66.1 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.66.1 * kernel-64kb-debugsource-6.4.0-150700.53.66.1 * kernel-64kb-debuginfo-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debugsource-6.4.0-150700.53.66.1 * kernel-zfcpdump-debuginfo-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.66.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.66.1.150700.17.39.1 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * kernel-livepatch-6_4_0-150700_53_66-default-debuginfo-1-150700.15.3.1 * kernel-livepatch-6_4_0-150700_53_66-default-1-150700.15.3.1 * kernel-default-livepatch-devel-6.4.0-150700.53.66.1 * kernel-default-livepatch-6.4.0-150700.53.66.1 * kernel-livepatch-SLE15-SP7_Update_18-debugsource-1-150700.15.3.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.66.2 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-6.4.0-150700.53.66.1 * kernel-syms-6.4.0-150700.53.66.1 * kernel-obs-build-debugsource-6.4.0-150700.53.66.1 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.66.1 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.66.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-devel-debuginfo-6.4.0-150700.53.66.1 * kernel-azure-debugsource-6.4.0-150700.53.66.1 * kernel-azure-debuginfo-6.4.0-150700.53.66.1 * kernel-azure-devel-6.4.0-150700.53.66.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-extra-debuginfo-6.4.0-150700.53.66.1 * kernel-default-debugsource-6.4.0-150700.53.66.1 * kernel-default-extra-6.4.0-150700.53.66.1 * kernel-default-debuginfo-6.4.0-150700.53.66.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.66.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40216.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46315.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1259764 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264484 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267953 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268159 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-15880 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 8 20:36:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 08 Jul 2026 20:36:51 -0000 Subject: SUSE-SU-2026:2799-1: important: Security update for the Linux Kernel Message-ID: <178354301146.547.8955293911889801313@530c474df1e7> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2799-1 Release Date: 2026-07-08T14:58:17Z Rating: important References: * bsc#1236743 * bsc#1255029 * bsc#1256668 * bsc#1259764 * bsc#1261256 * bsc#1261562 * bsc#1261604 * bsc#1262085 * bsc#1262392 * bsc#1262617 * bsc#1262618 * bsc#1262620 * bsc#1262655 * bsc#1262674 * bsc#1262748 * bsc#1262798 * bsc#1262993 * bsc#1263057 * bsc#1263072 * bsc#1263123 * bsc#1263124 * bsc#1263137 * bsc#1263178 * bsc#1263560 * bsc#1263563 * bsc#1263568 * bsc#1263573 * bsc#1263578 * bsc#1263581 * bsc#1263879 * bsc#1263880 * bsc#1263930 * bsc#1263934 * bsc#1263993 * bsc#1263996 * bsc#1263998 * bsc#1264001 * bsc#1264015 * bsc#1264045 * bsc#1264076 * bsc#1264080 * bsc#1264084 * bsc#1264116 * bsc#1264137 * bsc#1264145 * bsc#1264228 * bsc#1264230 * bsc#1264231 * bsc#1264236 * bsc#1264239 * bsc#1264241 * bsc#1264254 * bsc#1264258 * bsc#1264261 * bsc#1264263 * bsc#1264266 * bsc#1264286 * bsc#1264294 * bsc#1264320 * bsc#1264337 * bsc#1264437 * bsc#1264444 * bsc#1264449 * bsc#1264470 * bsc#1264549 * bsc#1264561 * bsc#1264562 * bsc#1264595 * bsc#1264603 * bsc#1264610 * bsc#1264612 * bsc#1264734 * bsc#1264741 * bsc#1264748 * bsc#1264763 * bsc#1264814 * bsc#1264974 * bsc#1265103 * bsc#1265113 * bsc#1265143 * bsc#1265211 * bsc#1265421 * bsc#1265628 * bsc#1265629 * bsc#1266008 * bsc#1266290 * bsc#1266390 * bsc#1266396 * bsc#1266397 * bsc#1266698 * bsc#1266700 * bsc#1266704 * bsc#1266705 * bsc#1266717 * bsc#1266734 * bsc#1266830 * bsc#1266840 * bsc#1266847 * bsc#1266878 * bsc#1266895 * bsc#1266899 * bsc#1266903 * bsc#1266916 * bsc#1266922 * bsc#1266928 * bsc#1266929 * bsc#1266933 * bsc#1267208 * bsc#1267228 * bsc#1267251 * bsc#1267361 * bsc#1267365 * bsc#1267369 * bsc#1267381 * bsc#1267387 * bsc#1267427 * bsc#1267430 * bsc#1267431 * bsc#1267437 * bsc#1267458 * bsc#1267567 * bsc#1267582 * bsc#1267591 * bsc#1267621 * bsc#1267624 * bsc#1267628 * bsc#1267635 * bsc#1267637 * bsc#1267640 * bsc#1267651 * bsc#1267654 * bsc#1267682 * bsc#1267684 * bsc#1267685 * bsc#1267697 * bsc#1267717 * bsc#1267722 * bsc#1267744 * bsc#1267816 * bsc#1267825 * bsc#1267918 * bsc#1267937 * bsc#1267953 * bsc#1267966 * bsc#1267993 * bsc#1268022 * bsc#1268037 * bsc#1268159 * bsc#1268237 * bsc#1268307 * bsc#1268335 * bsc#1268428 * bsc#1268660 * bsc#1268661 * bsc#1269022 * bsc#1269033 * bsc#1269090 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269136 * bsc#1269137 * bsc#1269184 * bsc#1269195 * bsc#1269199 * bsc#1269281 * bsc#1269310 * bsc#1269314 * bsc#1269397 * bsc#1269398 * bsc#1269418 * bsc#1269493 * bsc#1269506 * bsc#1269519 * bsc#1269574 * bsc#1269617 * bsc#1269678 * bsc#1269681 * bsc#1269798 * bsc#1269821 * bsc#1269884 * bsc#1270059 * jsc#PED-15880 * jsc#PED-16303 * jsc#PED-16305 Cross-References: * CVE-2025-10263 * CVE-2025-40216 * CVE-2025-40341 * CVE-2025-68822 * CVE-2025-71294 * CVE-2026-23451 * CVE-2026-31414 * CVE-2026-31429 * CVE-2026-31450 * CVE-2026-31452 * CVE-2026-31453 * CVE-2026-31462 * CVE-2026-31466 * CVE-2026-31469 * CVE-2026-31492 * CVE-2026-31495 * CVE-2026-31499 * CVE-2026-31500 * CVE-2026-31502 * CVE-2026-31555 * CVE-2026-31560 * CVE-2026-31592 * CVE-2026-31593 * CVE-2026-31647 * CVE-2026-31664 * CVE-2026-31665 * CVE-2026-31670 * CVE-2026-31674 * CVE-2026-31677 * CVE-2026-31680 * CVE-2026-31693 * CVE-2026-31697 * CVE-2026-31698 * CVE-2026-31699 * CVE-2026-31752 * CVE-2026-31759 * CVE-2026-31771 * CVE-2026-43010 * CVE-2026-43022 * CVE-2026-43023 * CVE-2026-43024 * CVE-2026-43028 * CVE-2026-43034 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43049 * CVE-2026-43053 * CVE-2026-43074 * CVE-2026-43077 * CVE-2026-43079 * CVE-2026-43080 * CVE-2026-43081 * CVE-2026-43083 * CVE-2026-43085 * CVE-2026-43086 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43094 * CVE-2026-43101 * CVE-2026-43107 * CVE-2026-43112 * CVE-2026-43119 * CVE-2026-43128 * CVE-2026-43139 * CVE-2026-43158 * CVE-2026-43171 * CVE-2026-43187 * CVE-2026-43198 * CVE-2026-43233 * CVE-2026-43238 * CVE-2026-43239 * CVE-2026-43284 * CVE-2026-43303 * CVE-2026-43336 * CVE-2026-43339 * CVE-2026-43345 * CVE-2026-43405 * CVE-2026-43420 * CVE-2026-43456 * CVE-2026-43469 * CVE-2026-43472 * CVE-2026-43491 * CVE-2026-43492 * CVE-2026-43502 * CVE-2026-45838 * CVE-2026-45840 * CVE-2026-45841 * CVE-2026-45848 * CVE-2026-45862 * CVE-2026-45870 * CVE-2026-45891 * CVE-2026-45894 * CVE-2026-45912 * CVE-2026-45940 * CVE-2026-45948 * CVE-2026-45961 * CVE-2026-45964 * CVE-2026-45965 * CVE-2026-45974 * CVE-2026-45985 * CVE-2026-46005 * CVE-2026-46028 * CVE-2026-46037 * CVE-2026-46053 * CVE-2026-46063 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46071 * CVE-2026-46076 * CVE-2026-46101 * CVE-2026-46112 * CVE-2026-46116 * CVE-2026-46119 * CVE-2026-46120 * CVE-2026-46123 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46150 * CVE-2026-46160 * CVE-2026-46162 * CVE-2026-46172 * CVE-2026-46173 * CVE-2026-46185 * CVE-2026-46197 * CVE-2026-46214 * CVE-2026-46227 * CVE-2026-46229 * CVE-2026-46244 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46259 * CVE-2026-46266 * CVE-2026-46273 * CVE-2026-46274 * CVE-2026-46289 * CVE-2026-46291 * CVE-2026-46315 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52908 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52943 * CVE-2026-52954 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-53016 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53052 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53122 * CVE-2026-53133 * CVE-2026-53138 * CVE-2026-53182 * CVE-2026-53253 * CVE-2026-53266 * CVE-2026-53281 * CVE-2026-53287 * CVE-2026-53359 * CVE-2026-53362 CVSS scores: * CVE-2025-10263 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-10263 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2025-40216 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2025-40341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68822 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-71294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31414 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31414 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31429 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31450 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31452 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31452 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31453 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31453 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31453 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31466 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31466 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31466 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31469 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31469 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31469 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31500 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31500 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31500 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31555 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31560 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31560 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31593 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31593 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-31593 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31647 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31647 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31664 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31664 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31665 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31665 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31665 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31674 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31674 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31693 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-31693 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31697 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31698 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31698 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31699 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31699 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31752 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31752 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43010 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43010 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43022 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43023 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43023 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43023 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43024 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43024 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43028 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43034 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43049 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43053 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43053 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43074 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43074 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43079 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43081 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43083 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43085 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43085 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43086 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43094 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43094 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43101 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43107 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43119 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43119 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43128 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43158 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43158 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43158 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43187 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43187 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43187 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43238 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43239 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43303 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43339 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43345 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43469 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43491 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43491 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45838 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45838 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-45838 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45841 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45848 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45848 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45862 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-45862 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-45862 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45870 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45870 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45891 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-45891 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-45891 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45894 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45894 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-45894 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45940 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45940 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45961 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45961 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45961 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45965 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45965 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45974 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45974 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46005 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46005 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46053 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46053 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46063 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46063 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46063 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46071 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46071 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46071 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46076 ( SUSE ): 8.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-46076 ( SUSE ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46076 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-46101 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46101 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-46101 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46112 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46112 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46119 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46119 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46123 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46123 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46123 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46160 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46160 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46185 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46214 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46214 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46244 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46244 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46259 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46273 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46289 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46289 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46289 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46291 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46291 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46315 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52908 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52908 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52908 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53052 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53052 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53122 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53122 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53138 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53138 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53266 ( SUSE ): 6.1 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53266 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53266 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53281 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53281 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Real Time Module 15-SP7 An update that solves 168 vulnerabilities, contains three features and has 14 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-10263: arm64: cputype: Add C1-Ultra definitions (bsc#1266290). * CVE-2025-40216: io_uring/rsrc: don't rely on user vaddr alignment (bsc#1259764). * CVE-2025-40341: futex: Don't leak robust_list pointer on exec race (bsc#1255029). * CVE-2025-68822: Input: alps - fix use-after-free bugs caused by dev3_register_work (bsc#1256668). * CVE-2025-71294: drm/amdgpu: fix NULL pointer issue buffer funcs (bsc#1264562). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31414: netfilter: nf_conntrack_expect: use expect->helper (bsc#1262085). * CVE-2026-31429: net: skb: fix cross-cache free of KFENCE-allocated skb head (bsc#1262392). * CVE-2026-31450: ext4: publish jinode after initialization (bsc#1262618). * CVE-2026-31452: ext4: convert inline data to extents when truncate exceeds inline size (bsc#1262620). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31466: mm/huge_memory: fix folio isn't locked in softleaf_to_folio() (bsc#1267825). * CVE-2026-31469: virtio_net: Fix UAF on dst_ops when IFF_XMIT_DST_RELEASE is cleared and napi_tx is false (bsc#1267816). * CVE-2026-31492: RDMA/irdma: Initialize free_qp completion before using it (bsc#1262748). * CVE-2026-31495: netfilter: ctnetlink: use netlink policy range checks (bsc#1262798). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31500: Bluetooth: hci_sync: Remove remaining dependencies of hci_request (bsc#1262993). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31555: futex: Clear stale exiting pointer in futex_lock_pi() retry path (bsc#1263178). * CVE-2026-31560: spi: spi-dw-dma: fix print error log when wait finish transaction (bsc#1263057). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31593: KVM: SEV: Reject attempts to sync VMSA of an already- launched/encrypted vCPU (bsc#1263124). * CVE-2026-31647: idpf: fix PREEMPT_RT raw/bh spinlock nesting for async VC handling (bsc#1263581). * CVE-2026-31664: xfrm: clear trailing padding in build_polexpire() (bsc#1263578). * CVE-2026-31665: netfilter: nft_ct: fix use-after-free in timeout object destroy (bsc#1263137). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31674: netfilter: ip6t_rt: reject oversized addrnr in rt_mt6_check() (bsc#1263568). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31693: cifs: some missing initializations on replay (bsc#1267744). * CVE-2026-31697: crypto: ccp: Don't attempt to copy ID to userspace if PSP command failed (bsc#1264116). * CVE-2026-31698: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed (bsc#1263880). * CVE-2026-31699: crypto: ccp: Don't attempt to copy CSR to userspace if PSP command failed (bsc#1263879). * CVE-2026-31752: bridge: br_nd_send: validate ND option lengths (bsc#1264045). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264076). * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43010: bpf: Reject sleepable kprobe_multi programs at attach time (bsc#1264015). * CVE-2026-43022: Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists (bsc#1264001). * CVE-2026-43023: Bluetooth: SCO: fix race conditions in sco_sock_connect() (bsc#1264137). * CVE-2026-43024: netfilter: nf_tables: reject immediate NF_QUEUE verdict (bsc#1263930). * CVE-2026-43028: netfilter: x_tables: ensure names are nul-terminated (bsc#1263934). * CVE-2026-43034: bnxt_en: set backing store type from query type (bsc#1263998). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43049: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure (bsc#1264080). * CVE-2026-43053: xfs: factor out xfs_attr3_node_entry_remove (bsc#1264084). * CVE-2026-43074: eventpoll: defer struct eventpoll free to RCU grace period (bsc#1264263). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1264470). * CVE-2026-43079: perf/x86/intel/uncore: Skip discovery table for offline dies (bsc#1264228). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43081: net: ipa: fix GENERIC_CMD register field masks for IPA v5.0+ (bsc#1264241). * CVE-2026-43083: net: ioam6: fix OOB and missing lock (bsc#1264266). * CVE-2026-43085: netfilter: nfnetlink_log: initialize nfgenmsg in NLMSG_DONE terminator (bsc#1264230). * CVE-2026-43086: ipvs: fix NULL deref in ip_vs_add_service error path (bsc#1264286). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43094: ixgbevf: add missing negotiate_features op to Hyper-V ops table (bsc#1264231). * CVE-2026-43101: ipv6: ioam: fix potential NULL dereferences in __ioam6_fill_trace_data() (bsc#1264239). * CVE-2026-43107: xfrm: account XFRMA_IF_ID in aevent size calculation (bsc#1264258). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43119: Bluetooth: hci_sync: annotate data-races around hdev->req_status (bsc#1264561). * CVE-2026-43128: RDMA/umem: Fix double dma_buf_unpin in failure path (bsc#1264612). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43158: xfs: fix freemap adjustments when adding xattrs to leaf blocks (bsc#1264595). * CVE-2026-43171: EFI/CPER: don't dump the entire memory region (bsc#1264549). * CVE-2026-43187: xfs: delete attr leaf freemap entries when empty (bsc#1264603). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43238: net/sched: act_skbedit: fix divide-by-zero in tcf_skbedit_hash() (bsc#1264320). * CVE-2026-43239: smb: client: prevent races in ->query_interfaces() (bsc#1264444). * CVE-2026-43303: mm/page_alloc: clear page->private in free_pages_prepare() (bsc#1264974). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43339: ipv6: prevent possible UaF in addrconf_permanent_addr() (bsc#1264763). * CVE-2026-43345: net: ipa: fix event ring index not programmed for IPA v5.0+ (bsc#1265103). * CVE-2026-43405: libceph: Use u32 for non-negative values in ceph_monmap_decode() (bsc#1264741). * CVE-2026-43420: ceph: fix i_nlink underrun during async unlink (bsc#1264814). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43469: xprtrdma: Decrement re_receiving on the early exit paths (bsc#1265143). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43491: net: qrtr: ns: Limit the maximum server registration per node (bsc#1265628). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45838: bpf: fix end-of-list detection in cgroup_storage_get_next_key() (bsc#1266396). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45841: netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO (bsc#1266390). * CVE-2026-45848: apparmor: fix NULL sock in aa_sock_file_perm (bsc#1266734). * CVE-2026-45862: iommu/vt-d: Flush cache for PASID table before using it (bsc#1266705). * CVE-2026-45870: SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths (bsc#1266704). * CVE-2026-45891: net: hns3: fix double free issue for tx spare buffer (bsc#1266717). * CVE-2026-45894: iommu/vt-d: Clear Present bit before tearing down PASID entry (bsc#1266895). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45940: net: stmmac: fix oops when split header is enabled (bsc#1266916). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45961: gfs2: fix memory leaks in gfs2_fill_super error path (bsc#1266933). * CVE-2026-45964: SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path (bsc#1266698). * CVE-2026-45965: apparmor: fix invalid deref of rawdata when export_binary is unset (bsc#1267208). * CVE-2026-45974: btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found (bsc#1266922). * CVE-2026-45985: ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O (bsc#1266700). * CVE-2026-46005: xfs: fix a resource leak in xfs_alloc_buftarg() (bsc#1267431). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267361). * CVE-2026-46053: net: rds: fix MR cleanup on copy error (bsc#1267427). * CVE-2026-46063: x86/shstk: Prevent deadlock during shstk sigreturn (bsc#1267228). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46071: KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 (bsc#1267591). * CVE-2026-46076: KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 (bsc#1267365). * CVE-2026-46101: netfilter: reject zero shift in nft_bitwise (bsc#1266878). * CVE-2026-46112: RDMA/hns: Fix unlocked call to hns_roce_qp_remove() (bsc#1267582). * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-46119: libceph: Fix slab-out-of-bounds access in auth message processing (bsc#1267628). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267640). * CVE-2026-46123: Bluetooth: virtio_bt: clamp rx length before skb_put (bsc#1267621). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46150: fanotify: fix false positive on permission events. * CVE-2026-46160: btrfs: fix missing last_unlink_trans update when removing a directory (bsc#1267624). * CVE-2026-46162: ice: fix double free in ice_sf_eth_activate() error path (bsc#1266840). * CVE-2026-46172: ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() (bsc#1266903). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46185: smb/client: fix out-of-bounds read in symlink_data() (bsc#1266830). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46214: vsock/virtio: fix accept queue count leak on transport mismatch (bsc#1267717). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267697). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46244: netfilter: nft_inner: Fix IPv6 inner_thoff desync (bsc#1267654). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46259: procfs: fix missing RCU protection when reading real_parent in do_task_stat() (bsc#1267685). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46273: ibmveth: Disable GSO for packets with small MSS (bsc#1265211 bsc#1267651). * CVE-2026-46289: lib/scatterlist: fix length calculations in extract_kvec_to_sg (bsc#1267966). * CVE-2026-46291: crypto: caam - guard HMAC key hex dumps in hash_digest_key (bsc#1267937). * CVE-2026-46315: io_uring/waitid: clear waitid info before copying it to userspace (bsc#1267953). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-52908: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible (bsc#1268661). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53052: ASoC: qcom: qdsp6: topology: check widget type before accessing data (bsc#1269314). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53122: btrfs: fix deadlock between reflink and transaction commit when using flushoncommit (bsc#1269418). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53138: drm/amd/display: Bound VBIOS record-chain walk loops (bsc#1269281). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269884). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53266: netfilter: bridge: make ebt_snat ARP rewrite writable (bsc#1269136). * CVE-2026-53281: iommu/vt-d: Avoid NULL pointer dereference or refcount corruption (bsc#1269519). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269493). The following non security issues were fixed: * accel/ivpu: Fix signed integer truncation in IPC receive (git-fixes). * ACPI: CPPC: Suppress UBSAN warning caused by field misuse (git-fixes). * ACPI: IPMI: Fix inverted interface check in ipmi_bmc_gone() (git-fixes). * ACPI: IPMI: Fix message kref handling on dead device (git-fixes). * ACPI: NFIT: core: Fix possible NULL pointer dereference (git-fixes). * ACPI: resource: Amend kernel-doc style (git-fixes). * agp/amd64: Fix broken error propagation in agp_amd64_probe() (git-fixes). * ALSA: aloop: Drop superfluous break (git-fixes). * ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser (git-fixes). * ALSA: cmipci: check snd_ctl_new1() return value (git-fixes). * ALSA: core: Fix unintuitive behavior of snd_power_ref_and_wait() (git- fixes). * ALSA: es1938: check snd_ctl_new1() return value (git-fixes). * ALSA: firewire: isight: bound the sample count to the packet payload (git- fixes). * ALSA: gus: check snd_ctl_new1() return value (git-fixes). * ALSA: hda/cs35l41: Fix firmware load work teardown (git-fixes). * ALSA: hda/hdmi: Add quirk for TUXEDO IBS14G6 (stable-fixes). * ALSA: ice1712: check snd_ctl_new1() return value (git-fixes). * ALSA: seq: Clear variable event pointer on read (git-fixes). * ALSA: seq: Fix kernel heap address leak in bounce_error_event() (git-fixes). * ALSA: seq: Fix partial userptr event expansion (git-fixes). * ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() (git-fixes). * ALSA: seq: midi: Serialize output teardown with event_input (git-fixes). * ALSA: timer: Fix UAF at snd_timer_user_params() (stable-fixes). * ALSA: usb-audio: avoid kobject path lookup in DualSense match (git-fixes). * ALSA: usb-audio: Kill MIDI 2.0 URBs before freeing endpoints (git-fixes). * ALSA: usb-audio: Propagate errors in scarlett_ctl_enum_put() (git-fixes). * ALSA: usb-audio: Propagate US-16x08 write errors in route/mix EQ-switch put callbacks (git-fixes). * ALSA: usb-audio: Roll back quirk control caches on write errors (git-fixes). * ALSA: usb-audio: Update Babyface Pro control caches only after successful writes (git-fixes). * ALSA: usb-audio: Update US-16x08 EQ/comp shadow state after successful writes (git-fixes). * ALSA: virtio: Add missing 384 kHz PCM rate mapping (git-fixes). * ALSA: ymfpci: check snd_ctl_new1() return value (git-fixes). * ASoC: adau1372: Clear PLL_EN on failed PLL lock without reset GPIO (git- fixes). * ASoC: codecs: hdac_hdmi: Validate written enum value (git-fixes). * ASoC: cs35l56: Cleanup if component_probe fails (git-fixes). * ASoC: cs35l56: Don't leave parent IRQ disabled if system_suspend fails (git- fixes). * ASoC: cs35l56: Fix missing calls to wm_adsp2_remove() (git-fixes). * ASoC: fsl: fsl_audmix: Validate written enum values (git-fixes). * ASoC: fsl_asrc_dma: fix eDMA maxburst misalignment with channel count (git- fixes). * ASoC: mediatek: mt8183: Release reserved memory on cleanup (git-fixes). * ASoC: mediatek: mt8192: Release reserved memory on cleanup (git-fixes). * ASoC: meson: aiu: Validate written enum values (git-fixes). * ASoC: qcom: q6apm: fix NULL pointer dereference in graph_callback (git- fixes). * ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (git-fixes). * ASoC: SOF: ipc3-control: Fix TOCTOU in bytes_put and bytes_get (git-fixes). * ASoC: SOF: ipc3-control: Use overflow checks in control_update size calc (git-fixes). * ASoC: SOF: ipc3-control: Validate size in snd_sof_update_control (git- fixes). * ASoC: SOF: ipc4-control: Fix TOCTOU in sof_ipc4_bytes_put (git-fixes). * ASoC: SOF: topology: validate vendor array size before parsing (git-fixes). * ASoC: tegra: tegra210_ahub: Validate written enum value (git-fixes). * ASoC: tlv320aic3x: restrict CLKDIV bypass Q values in dual-rate mode (git- fixes). * ASoC: topology: Check PCM and DAI name strings before use (git-fixes). * ASoC: wm_adsp: Fix NULL dereference when removing firmware controls (git- fixes). * batman-adv: bla: annotate lasttime access with READ/WRITE_ONCE (git-fixes). * batman-adv: tp_meter: add only finished tp_vars to lists (git-fixes). * batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd (git-fixes). * batman-adv: tp_meter: avoid window underflow (git-fixes). * batman-adv: tp_meter: fix fast recovery precondition (git-fixes). * batman-adv: tp_meter: handle seqno wrap-around for fast recovery detection (git-fixes). * batman-adv: tp_meter: initialize dec_cwnd explicitly (git-fixes). * batman-adv: tp_meter: initialize dup_acks explicitly (git-fixes). * batman-adv: tp_meter: keep unacked list in ascending ordered (git-fixes). * Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path (git-fixes). * Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() (git- fixes). * Bluetooth: btusb: fix use-after-free on marvell probe failure (git-fixes). * Bluetooth: btusb: fix use-after-free on registration failure (git-fixes). * Bluetooth: btusb: fix wakeup irq devres lifetime (git-fixes). * Bluetooth: btusb: fix wakeup source leak on probe failure (git-fixes). * Bluetooth: eir: Fix stack OOB write when prepending the Flags AD (git- fixes). * Bluetooth: hci: validate codec capability element length (git-fixes). * Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non- serdev device (git-fixes). * Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig (stable- fixes). * Bluetooth: vhci: validate devcoredump state before side effects (git-fixes). * bnxt_en: Fix NULL pointer dereference (bsc#1268307). * bus: mhi: ep: Add missing state_lock protection for mhi_state access (git- fixes). * bus: mhi: ep: Fix potential deadlock in mhi_ep_reset_worker() (git-fixes). * bus: mhi: ep: Protect mhi_ep_handle_syserr() in the error path (git-fixes). * char: tlclk: fix use-after-free in tlclk_cleanup() (git-fixes). * crypto: af_alg - Cap AEAD AD length to 0x80000000 (git-fixes). * crypto: amlogic - avoid double cleanup in meson_crypto_probe() (git-fixes). * crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (git- fixes). * crypto: atmel-sha204a - fix blocking and non-blocking rng logic (git-fixes). * crypto: cavium/cpt - fix DMA cleanup using wrong loop index (git-fixes). * crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one (git-fixes). * crypto: ccp - Treat zero-length cert chain as query for blob lengths (git- fixes). * crypto: drbg - Fix drbg_max_addtl() on 64-bit kernels (git-fixes). * crypto: drbg - Fix returning success on failure in CTR_DRBG (git-fixes). * crypto: drbg - Fix the fips_enabled priority boost (git-fixes). * crypto: ecc - Fix carry overflow in vli multiplication (git-fixes). * crypto: ecrdsa - fix unknown OID check in ecrdsa_param_curve (git-fixes). * crypto: hisilicon/qm - disable error report before flr (git-fixes). * crypto: marvell/octeontx - fix DMA cleanup using wrong loop index (git- fixes). * crypto: pcrypt - restore callback for non-parallel fallback (git-fixes). * crypto: qat - protect service table iterations with service_lock (git- fixes). * crypto: qat - validate RSA CRT component lengths (git-fixes). * crypto: rng - Free default RNG on module exit (git-fixes). * dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK (git-fixes). * dmaengine: Fix possible use after free (git-fixes). * dmaengine: imx-sdma: Refine spba bus searching in probe (git-fixes). * dmaengine: qcom: gpi: set DMA_PRIVATE capability (git-fixes). * dmaengine: tegra: Fix burst size calculation (git-fixes). * driver core: reject devices with unregistered buses (git-fixes). * driver core: use READ_ONCE() for dev->driver in dev_has_sync_state() (git- fixes). * Drivers: hv: vmbus: Improve the logic of reserving fb_mmio on Gen2 VMs (git- fixes). * drm/amd/display: add missing CSC entries for BT.2020 for DCE IPs (stable- fixes). * drm/amd/display: Add missing kdoc for ALLM parameters (git-fixes). * drm/amd/display: Clamp VBIOS HDMI retimer register count to array size (stable-fixes). * drm/amd/pm: fix smu13 power limit default/cap calculation (stable-fixes). * drm/amd/pm: mark metrics.energy_accumulator is invalid for smu 14.0.2 (stable-fixes). * drm/amd/pm: remove trailing semicolon from AMDGPU_PM_POLICY_ATTR macro (git- fixes). * drm/amd/pm: smu_v14_0_0: use SoftMin for gfxclk in set_soft_freq_limited_range (stable-fixes). * drm/amdgpu: Fix amdgpu_bo_move() when old_mem and new_mem are both GTT (git- fixes). * drm/amdgpu: fix integer overflow in amdgpu_gem_align_pitch() (git-fixes). * drm/amdgpu: initialize irq.lock spinlock earlier (git-fixes). * drm/amdgpu: restart the CS if some parts of the VM are still invalidated (stable-fixes). * drm/amdgpu: set sub_block_index for mca ras sub-blocks (git-fixes). * drm/amdgpu: skip already suspended IP blocks in ip_suspend_phase2 (git- fixes). * drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 (git-fixes). * drm/amdkfd: always resume_all after suspend_all (git-fixes). * drm/amdkfd: Avoid double-unpin of DOORBELL/MMIO BOs on free (git-fixes). * drm/amdkfd: Check for pdd drm file first in CRIU restore path (stable- fixes). * drm/amdkfd: fix list_del corruption in kfd_criu_resume_svm (git-fixes). * drm/amdkfd: fix NULL pointer bug in svm_range_set_attr (stable-fixes). * drm/amdkfd: Use exclusive bounds for SVM split alignment checks (git-fixes). * drm/amdkfd: Validate CRIU-restored IDs before idr_alloc (git-fixes). * drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() (git-fixes). * drm/dp/mst: fix buffer overflows in sideband chunk accumulation (git-fixes). * drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (git- fixes). * drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (git- fixes). * drm/dp: Add eDP 1.5 bit definition (stable-fixes). * drm/edid: fix OOB read in drm_parse_tiled_block() (git-fixes). * drm/gpuvm: Do not prepare NULL objects (git-fixes). * drm/hisilicon/hibmc: move display contrl config to hibmc_probe() (git- fixes). * drm/hisilicon/hibmc: use clock to look up the PLL value (git-fixes). * drm/hyperv: use VMBUS_RING_SIZE() (git-fixes). * drm/i915/gem: Add missing nospec on parallel submit slot (git-fixes). * drm/i915/gem: Fix phys BO pread/pwrite with offset (git-fixes). * drm/i915/psr: Add defininitions for INTEL_WA_REGISTER_CAPS DPCD register (stable-fixes). * drm/i915: clear CRTC color blob pointers after dropping refs (git-fixes). * drm/imagination: Count paired job fence as dependency in prepare_job() (git- fixes). * drm/imagination: Fit paired fragment job in the correct CCCB (git-fixes). * drm/msm/dp: fix HPD state status bit shift value (git-fixes). * drm/msm/dp: Fix the ISR_* enum values (git-fixes). * drm/nouveau/acr: fix missing nvkm_done() in error path of nvkm_acr_oneinit() (git-fixes). * drm/nouveau/bios: specify correct display fuse register for Ampere and Ada (git-fixes). * drm/nouveau: fix reversed error cleanup order in ucopy functions (git- fixes). * drm/panthor: Fix kernel-doc warning in panthor_sched.c (git-fixes). * drm/radeon: fix integer overflow in radeon_align_pitch() (git-fixes). * drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (git- fixes). * drm/rockchip: cdn-dp: add missing check in cdn_dp_config_video() (git- fixes). * drm/syncobj: Fix memory leak in drm_syncobj_find_fence() (git-fixes). * drm/tegra: dc: Fix device node reference leak in tegra_dc_has_output() (git- fixes). * drm/tegra: Fix iommu_map_sgtable() return value check (git-fixes). * drm/tidss: Drop extra drm_mode_config_reset() call (git-fixes). * drm/tidss: Fix missing drm_bridge_add() call (git-fixes). * drm/vc4: fix krealloc() memory leak (git-fixes). * drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() (git-fixes). * drm/virtio: Fix driver removal with disabled KMS (git-fixes). * drm/xe: fix refcount leak in xe_range_fence_insert() (git-fixes). * drm: renesas: rzg2l_mipi_dsi: Increase reset deassertion delay (git-fixes). * ethtool: provide customized dim profile management (bsc#1261256). * fbdev: broadsheetfb: fix potential memory leak in broadsheetfb_probe() (git- fixes). * fbdev: hecubafb: fix potential memory leak in hecubafb_probe() (git-fixes). * fbdev: i740fb: fix potential memory leak in i740fb_probe() (git-fixes). * fbdev: metronomefb: fix potential memory leak in metronomefb_probe() (git- fixes). * fbdev: modedb: Fix misaligned fields in the 1920x1080-60 mode (git-fixes). * fbdev: nvidia: fix potential memory leak in nvidiafb_probe() (git-fixes). * fbdev: radeon: fix potential memory leak in radeonfb_pci_register() (git- fixes). * fbdev: s3fb: fix potential memory leak in s3_pci_probe() (git-fixes). * fbdev: sm501fb: Fix buffer errors in OF binding code (git-fixes). * fbdev: sm712: Fix operator precedence in big_swap macro (git-fixes). * fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() (git-fixes). * fbdev: tridentfb: fix potential memory leak in trident_pci_probe() (git- fixes). * fbdev: uvesafb: fix potential memory leak in uvesafb_probe() (git-fixes). * fbdev: vesafb: fix memory leak in vesafb_probe() (git-fixes). * firmware: arm_scmi: Fix OOB in scmi_power_name_get() (git-fixes). * firmware: arm_scmi: Read sensor config as 32-bit value (git-fixes). * firmware_loader: fix device reference leak in firmware_upload_register() (git-fixes). * firmware_loader: Fix recursive lock in device_cache_fw_images() (git-fixes). * fpga: dfl: add bounds check in dfh_get_param_size() (git-fixes). * fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() (git-fixes). * fpga: region: fix use-after-free in child_regions_with_firmware() (git- fixes). * gpio: mvebu: fix NULL pointer dereference in suspend/resume (git-fixes). * gpu: host1x: Allow entries in BO caches to be freed (git-fixes). * gpu: host1x: Fix iommu_map_sgtable() return value check (git-fixes). * HID: logitech-hidpp: remove excess kernel-doc member in hidpp_scroll_counter (git-fixes). * HID: quirks: Add ALWAYS_POLL quirk for SIGMACHIP USB mouse (stable-fixes). * HID: wacom: stop hardware after post-start probe failures (git-fixes). * HID: wiimote: Fix table layout and whitespace errors (git-fixes). * hv: utils: handle and propagate errors in kvp_register (git-fixes). * hv_balloon: Simplify data output in hv_balloon_debug_show() (git-fixes). * hwmon: (it87) Clamp negative values to zero in set_fan() (git-fixes). * hwrng: jh7110 - fix refcount leak in starfive_trng_read() (git-fixes). * hwrng: virtio: clamp device-reported used.len at copy_data() (git-fixes). * hyperv: Clean up and fix the guest ID comment in hvgdk.h (git-fixes). * i2c: core: fix irq domain leak on adapter registration failure (git-fixes). * i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl (stable-fixes). * i2c: mpc: Fix timeout calculations (git-fixes). * i2c: qcom-cci: Fix NULL pointer dereference in cci_remove() (git-fixes). * i2c: stm32f7: fix timing computation ignoring i2c-analog-filter (git-fixes). * i2c: stm32f7: truncate clock period instead of rounding it (git-fixes). * i2c: tegra: Fix NOIRQ suspend/resume (git-fixes). * i3c: master: Prevent reuse of dynamic address on device add failure (git- fixes). * ice: ptp: don't WARN when controlling PF is unavailable (bsc#1267251). * iio: accel: mma8452: handle I2C read error(s) in mma8452_read() (git-fixes). * iio: adc: npcm: Convert to platform remove callback returning void (stable- fixes). * iio: adc: xilinx-ams: fix out-of-bounds channel lookup in event handling (git-fixes). * iio: chemical: scd30: Cleanup initializations and fix sign-extension bug (git-fixes). * iio: chemical: scd30: fix division by zero in write_raw (git-fixes). * iio: chemical: scd30: Use guard(mutex) to allow early returns (stable- fixes). * iio: gyro: bmg160: bail out when bandwidth/filter is not in table (git- fixes). * iio: gyro: bmg160: wait full startup time after mode change at probe (git- fixes). * iio: light: opt3001: fix missing state reset on timeout (git-fixes). * iio: light: si1133: prevent race condition on timeout (git-fixes). * iio: light: si1133: reset counter to prevent race condition (git-fixes). * iio: light: veml6030: fix channel type when pushing events (git-fixes). * iio: magnetometer: ak8975: Add missed pm_runtime_put_autosuspend() call (git-fixes). * iio: magnetometer: ak8975: fix potential kernel stack memory leak (git- fixes). * iio: tcs3472: power down chip on probe failure (git-fixes). * iio: temperature: ltc2983: Fix reinit_completion() called after conversion start (git-fixes). * Input: atkbd - add DMI quirk for Lenovo Yoga Air 14 (83QK) (stable-fixes). * Input: elan_i2c - validate firmware size before use (stable-fixes). * Input: synaptics - add LEN2058 to SMBus passlist for ThinkPad E490 (stable- fixes). * Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count (git-fixes). * Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count (git- fixes). * Input: xpad - add "Nova 2 Lite" from GameSir (stable-fixes). * Input: xpad - add support for ASUS ROG RAIKIRI II (stable-fixes). * iommu/s390: allow larger region tables (jsc#PED-15880). * iommu/s390: Fix memory corruption when using identity domain (jsc#PED-15880). * iommu/s390: handle IOAT registration based on domain (jsc#PED-15880). * iommu/s390: implement iommu passthrough via identity domain (jsc#PED-15880). * iommu/s390: set appropriate IOTA region type (jsc#PED-15880). * iommu/s390: support cleanup of additional table regions (jsc#PED-15880). * iommu/s390: support iova_to_phys for additional table regions (jsc#PED-15880). * iommu/s390: support map/unmap for additional table regions (jsc#PED-15880). * KVM: arm64: Discard PC update state on vcpu reset (git-fixes). * KVM: arm64: Guard against NULL vcpu on VHE hyp panic path (git-fixes). * KVM: arm64: PMU: Preserve AArch32 counter low bits (git-fixes). * KVM: arm64: Treat vCPU with pending SError as runnable (git-fixes). * KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits (git-fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: arm64: Wake-up from WFI when iqrchip is in userspace (git-fixes). * KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation (git-fixes). * KVM: nSVM: Ensure AVIC is inhibited when restoring a vCPU to guest mode (git-fixes). * KVM: nSVM: Mark all of vmcb02 dirty when restoring nested state (git-fixes). * KVM: nSVM: Set exit_code_hi to -1 when synthesizing SVM_EXIT_ERR (failed VMRUN) (git-fixes). * KVM: s390: Limit adapter indicator access to mapped page (bsc#1268159). * KVM: SEV: Ignore MMIO requests of length '0' (git-fixes). * KVM: SEV: Ignore Port I/O requests of length '0' (git-fixes). * KVM: SVM: Allow KVM_SET_NESTED_STATE to clear GIF when SVME==0 (git-fixes). * KVM: SVM: check validity of VMCB controls when returning from SMM (git- fixes). * KVM: SVM: Don't set GIF when clearing EFER.SVME (git-fixes). * KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path (git-fixes). * KVM: SVM: Flush the current TLB when transitioning from xAVIC => x2AVIC (git-fixes). * KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (git-fixes). * KVM: SVM: Truncate INVLPGA address in compatibility mode (git-fixes). * KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode (git-fixes). * KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level (git-fixes). * KVM: x86/mmu: Fix UBSAN warning when reading nx_huge_pages parameter (git- fixes). * KVM: x86/mmu: Recursively zap orphaned nested TDP shadow pages on emulated writes (git-fixes). * KVM: x86: hyper-v: Bound the bank index when querying sparse banks (git- fixes). * KVM: x86: ioapic: Use old_dest_mode consistently in ioapic_write_indirect() (git-fixes). * KVM: x86: Move update_cr8_intercept() to lapic.c (git-fixes). * KVM: x86: Unconditionally recompute CR8 intercept on PPR update (git-fixes). * leds: uleds: Fix potential buffer overread (git-fixes). * linux/dim: move useful macros to .h file (bsc#1261256). * loadpin: Prevent SECURITY_LOADPIN_ENFORCE=y without module decompression (jsc#PED-16303). * loadpin: remove MODULE_COMPRESS_NONE as it is no longer supported (jsc#PED-16303). * mailbox: mtk-adsp: fix UAF during device teardown (git-fixes). * media: aspeed: fix missing of_reserved_mem_device_release() on probe failure (git-fixes). * media: cec: seco: unregister adapter on IR probe failure (git-fixes). * media: cedrus: Fix failure to clean up hardware on probe failure (git- fixes). * media: cedrus: Fix missing cleanup in error path (git-fixes). * media: cedrus: skip invalid H.264 reference list entries (git-fixes). * media: marvell-cam: fix missing pci_disable_device() on remove (git-fixes). * media: mtk-jpeg: cancel workqueue on release for supported platforms only (git-fixes). * media: pci: dm1105: Free allocated workqueue (git-fixes). * media: ti: vpe: unwind v4l2 device registration on probe error (git-fixes). * media: v4l2-ctrls: validate HEVC active reference counts (git-fixes). * media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si (git-fixes). * media: vidtv: fix reference leak on failed device registration (git-fixes). * media: vimc: fix reference leak on failed device registration (git-fixes). * media: vpif_capture: fix OF node reference imbalance (git-fixes). * misc: fastrpc: fix DMA address corruption due to find_vma misuse (git- fixes). * misc: fastrpc: Fix NULL pointer dereference in rpmsg callback (git-fixes). * misc: fastrpc: fix use-after-free of fastrpc_user in workqueue context (git- fixes). * misc: fastrpc: fix use-after-free race in fastrpc_map_create (git-fixes). * module: fix init_module_from_file() error handling (jsc#PED-16303). * module: make waiting for a concurrent module loader interruptible (jsc#PED-16303). * module: Split modules_install compression and in-kernel decompression (jsc#PED-16303). * module: split up 'finit_module()' into init_module_from_file() helper (jsc#PED-16303). * module: warn about excessively long module waits (jsc#PED-16303). * modules: catch concurrent module loads, treat them as idempotent (jsc#PED-16303). * mtd: maps: vmu-flash: fix NULL pointer dereference in initialization (git- fixes). * mtd: rawnand: fix condition in 'nand_select_target()' (git-fixes). * mtd: rawnand: pl353: fix probe resource allocation (git-fixes). * mtd: slram: remove failed entries from the device list (git-fixes). * mtd: spi-nor: Drop duplicate Kconfig dependency (git-fixes). * mtd: spi-nor: swp: Improve locking user experience (git-fixes). * net: aquantia: Add missing descriptor cache invalidation on ATL2 (bsc#1268428). * net: ethtool: add ethtool COALESCE_RX_CQE_FRAMES/NSECS (bsc#1261256). * net: mana: Add ethtool counters for RX CQEs in coalesced type (bsc#1261256). * net: mana: Add support for PF device 0x00C1 (bsc#1268237). * net: mana: Add support for RX CQE Coalescing (bsc#1261256). * net: mana: Allocate interrupt context for each EQ when creating vPort (git- fixes). * net: mana: Create separate EQs for each vPort (git-fixes). * net: mana: Fall back to standard MTU when PF reports adapter_mtu of 0 (git- fixes). * net: mana: guard TX wq object destroy with INVALID_MANA_HANDLE check (git- fixes). * net: mana: initialize gdma queue id to INVALID_QUEUE_ID (git-fixes). * net: mana: Introduce GIC context with refcounting for interrupt management (git-fixes). * net: mana: Optimize irq affinity for low vcpu configs (git-fixes). * net: mana: Query device capabilities and configure MSI-X sharing for EQs (git-fixes). * net: mana: Use GIC functions to allocate global EQs (git-fixes). * nfc: hci: fix out-of-bounds read in HCP header parsing (git-fixes). * nfc: llcp: Fix use-after-free in llcp_sock_release() (git-fixes). * nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (git-fixes). * of: cpu: add check in __of_find_n_match_cpu_property() (git-fixes). * page_pool: Move pp_magic check into helper functions (bsc#1261562). * page_pool: Track DMA-mapped pages and unmap them when destroying the pool (bsc#1261562). * platform/x86: intel-hid: Protect ACPI notify handler against recursion (git- fixes). * platform/x86: xo15-ebook: Fix wakeup source and GPE handling (git-fixes). * PM: sleep: Use complete() in device_pm_sleep_init() (git-fixes). * power: reset: linkstation-poweroff: fix use-after-free in the linkstation_poweroff_init() (git-fixes). * power: supply: charger-manager: fix refcount leak in is_full_charged() (git- fixes). * power: supply: core: fix supplied_from allocations (git-fixes). * power: supply: cpcap-battery: Fix missing nvmem_device_put() causing reference leak (git-fixes). * powerpc/boot: Allow text relocations for pseries wrapper with binutils 2.46+ (git-fixes). * powerpc/fadump: define MIN_RMA in bytes rather than MB (bsc#1236743 git- fixes). * RDMA/mana_ib: Allocate interrupt contexts on EQs (git-fixes). * RDMA/mana_ib: Use ib_get_eth_speed for reporting port speed (git-fixes). * rtc: abx80x: fix the RTC_VL_CLR clearing all status flags (git-fixes). * rtc: cmos: unregister HPET IRQ handler on probe failure (git-fixes). * rtc: ds1307: Fix off-by-one issue with wday for rx8130 (git-fixes). * rtc: ds1307: handle oscillator stop flag for ds1337/ds1339/ds3231 (git- fixes). * rtc: mpfs: fix counter upload completion condition (git-fixes). * rtc: msc313: fix NULL deref in shared IRQ handler at probe (git-fixes). * s390/pci: check for relaxed translation capability (jsc#PED-15880). * s390/pci: Fix dev.dma_range_map missing sentinel element (jsc#PED-15880). * s390/pci: store DMA offset in bus_dma_region (jsc#PED-15880). * scripts/submit_branch: add SLE15-SP7 submission script. * scsi: storvsc: Replace symbolic permissions with octal (git-fixes). * scsi: target: Fix hexadecimal CHAP_I handling (git-fixes). * selftests/bpf: Add BPF_STRICT_BUILD toggle (bsc#1269617). * selftests/bpf: Allow test_progs to link with a partial object set (bsc#1269617). * selftests/bpf: Fix test_kmods KDIR to honor O= and distro kernels (bsc#1269617). * selftests/bpf: Make skeleton headers order-only prerequisites of .test.d (bsc#1269617). * selftests/bpf: Provide weak definitions for cross-test functions (bsc#1269617). * selftests/bpf: Skip tests whose objects were not built (bsc#1269617). * selftests/bpf: Tolerate benchmark build failures (bsc#1269617). * selftests/bpf: Tolerate BPF and skeleton generation failures (bsc#1269617). * selftests/bpf: Tolerate missing files during install (bsc#1269617). * selftests/bpf: Tolerate test file compilation failures (bsc#1269617). * serdev: make serdev_bus_type const (stable-fixes). * serial: 8250: dispatch SysRq character in serial8250_handle_irq() (git- fixes). * serial: 8250_dw: dispatch SysRq character in dw8250_handle_irq() (git- fixes). * slimbus: qcom-ngd-ctrl: fix OF node refcount (git-fixes). * soc: fsl: qe: panic on ioremap() failure in qe_reset() (git-fixes). * soc: ti: k3-ringacc: Fix access mode for k3_ringacc_ring_pop_tail_io/proxy (git-fixes). * spi: at91-usart: drop dead runtime pm support (git-fixes). * spi: dw: fix wrong BAUDR setting after resume (git-fixes). * spi: ep93xx: fix double-free of zeropage on DMA setup failure (git-fixes). * spi: fsl-lpspi: replace dmaengine_terminate_all() with dmaengine_terminate_sync() (git-fixes). * spi: fsl-lpspi: terminate the RX channel on TX prepare failure path (git- fixes). * spi: meson-spifc: fix runtime PM leak on remove (git-fixes). * spi: rpc-if: Use correct device for hardware reinitialization on resume (git-fixes). * spi: uniphier: Fix completion initialization order before devm_request_irq() (git-fixes). * spi: xilinx: use FIFO occupancy register to determine buffer size (git- fixes). * Split off kABI workaround for bsc#1267458 (bsc#1267458). * staging: most: video: avoid double free on video register failure (git- fixes). * staging: nvec: fix use-after-free in nvec_rx_completed() (git-fixes). * thermal: hwmon: Fix critical temperature attribute removal (git-fixes). * thermal: intel: Fix dangling resources on thermal_throttle_online() failure (git-fixes). * thunderbolt: Bound root directory content to block size (git-fixes). * thunderbolt: Clamp XDomain response data copy to allocation size (git- fixes). * thunderbolt: Limit XDomain response copy to actual frame size (git-fixes). * thunderbolt: Reject zero-length property entries in validator (git-fixes). * thunderbolt: Validate XDomain request packet size before type cast (git- fixes). * tpm: fix event_size output in tpm1_binary_bios_measurements_show (git- fixes). * tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() (git-fixes). * usb: core: Fix SuperSpeed root hub wMaxPacketSize (stable-fixes). * usb: core: Fix up Interrupt IN endpoints with bogus wBytesPerInterval (stable-fixes). * usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo (git-fixes). * usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() (git- fixes). * usb: host: max3421: Reject hub port requests for non-existent ports (git- fixes). * USB: quirks: add NO_LPM for Lenovo ThinkPad USB-C Dock Gen2 hub controllers (stable-fixes). * USB: serial: io_ti: fix heap overflow in build_i2c_fw_hdr() (git-fixes). * USB: serial: io_ti: fix heap overflow in get_manuf_info() (git-fixes). * USB: serial: kl5kusb105: fix bulk-out buffer overflow (git-fixes). * USB: serial: option: add MeiG SRM813Q (stable-fixes). * USB: serial: option: add usb-id for Dell Wireless DW5826e-m (stable-fixes). * usb: storage: Add quirks for PNY Elite Portable SSD (stable-fixes). * usb: typec: altmodes/displayport: validate count before reading Status Update VDO (stable-fixes). * usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT (stable-fixes). * usb: typec: ucsi: ccg: reject firmware images without a ':' record header (stable-fixes). * usb: typec: ucsi: displayport: NAK DP_CMD_CONFIGURE without a payload VDO (stable-fixes). * usb: typec: ucsi: validate connector number in ucsi_connector_change() (stable-fixes). * usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() (stable-fixes). * vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write (git-fixes). * watchdog/hpwdt: Refine hpwdt message for UV platform (bsc#1269199). * watchdog: apple: Add "apple,t8103-wdt" compatible (git-fixes). * watchdog: sp5100_tco: Use EFCH MMIO for newer Hygon FCH (git-fixes). * watchdog: sprd_wdt: Remove redundant sprd_wdt_disable() on register failure (git-fixes). * watchdog: unregister PM notifier on watchdog unregister (git-fixes). * wifi: ath9k: fix OOB access from firmware tx status queue ID (git-fixes). * wifi: ath11k: fix warning when unbinding (git-fixes). * wifi: cfg80211: fix grammar in MLO group key error message (git-fixes). * wifi: mac80211: fix monitor mode frame capture for real chanctx drivers (git-fixes). * wifi: mt76: fix argument to ieee80211_is_first_frag() (git-fixes). * wifi: mt76: mt7915: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7921: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7925: clean up DMA on probe failure (git-fixes). * wifi: mt76: mt7925: fix potential tx_retries underflow (git-fixes). * wifi: mt76: mt7996: fix potential tx_retries underflow (git-fixes). * wifi: rtlwifi: rtl8821ae: Fix C2H bit location in RX descriptor (git-fixes). * wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer (git-fixes). * wifi: rtw88: increase TX report timeout to fix race condition (git-fixes). * wifi: rtw88: usb: fix memory leaks on USB write failures (git-fixes). * wifi: rtw89: Correct data type for scan index to avoid infinite loop (git- fixes). * wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (git- fixes). * wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication (git-fixes). * wifi: wcn36xx: fix OOB read from short trigger BA firmware response (git- fixes). * x86/platform/uv: Expose the uv_hub_type() interface (jsc#PED-16305). * x86/tsc: Disable clocksource watchdog checking on recent and future UV platforms (jsc#PED-16305). * X.509: Fix validation of ASN.1 certificate header (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2799=1 * SUSE Real Time Module 15-SP7 zypper in -t patch SUSE-SLE-Module-RT-15-SP7-2026-2799=1 ## Package List: * SUSE Real Time Module 15-SP7 (x86_64) * ocfs2-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * cluster-md-kmp-rt-6.4.0-150700.7.62.1 * kernel-rt-debugsource-6.4.0-150700.7.62.1 * kernel-syms-rt-6.4.0-150700.7.62.1 * kernel-rt-devel-6.4.0-150700.7.62.1 * cluster-md-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * kernel-rt-devel-debuginfo-6.4.0-150700.7.62.1 * ocfs2-kmp-rt-6.4.0-150700.7.62.1 * gfs2-kmp-rt-6.4.0-150700.7.62.1 * dlm-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * kernel-rt-debuginfo-6.4.0-150700.7.62.1 * gfs2-kmp-rt-debuginfo-6.4.0-150700.7.62.1 * dlm-kmp-rt-6.4.0-150700.7.62.1 * SUSE Real Time Module 15-SP7 (nosrc x86_64) * kernel-rt-6.4.0-150700.7.62.1 * SUSE Real Time Module 15-SP7 (noarch) * kernel-devel-rt-6.4.0-150700.7.62.1 * kernel-source-rt-6.4.0-150700.7.62.1 * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_62-rt-debuginfo-1-150700.1.3.1 * kernel-livepatch-SLE15-SP7-RT_Update_17-debugsource-1-150700.1.3.1 * kernel-livepatch-6_4_0-150700_7_62-rt-1-150700.1.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-10263.html * https://www.suse.com/security/cve/CVE-2025-40216.html * https://www.suse.com/security/cve/CVE-2025-40341.html * https://www.suse.com/security/cve/CVE-2025-68822.html * https://www.suse.com/security/cve/CVE-2025-71294.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31414.html * https://www.suse.com/security/cve/CVE-2026-31429.html * https://www.suse.com/security/cve/CVE-2026-31450.html * https://www.suse.com/security/cve/CVE-2026-31452.html * https://www.suse.com/security/cve/CVE-2026-31453.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31466.html * https://www.suse.com/security/cve/CVE-2026-31469.html * https://www.suse.com/security/cve/CVE-2026-31492.html * https://www.suse.com/security/cve/CVE-2026-31495.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31500.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31555.html * https://www.suse.com/security/cve/CVE-2026-31560.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31593.html * https://www.suse.com/security/cve/CVE-2026-31647.html * https://www.suse.com/security/cve/CVE-2026-31664.html * https://www.suse.com/security/cve/CVE-2026-31665.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31674.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31693.html * https://www.suse.com/security/cve/CVE-2026-31697.html * https://www.suse.com/security/cve/CVE-2026-31698.html * https://www.suse.com/security/cve/CVE-2026-31699.html * https://www.suse.com/security/cve/CVE-2026-31752.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43010.html * https://www.suse.com/security/cve/CVE-2026-43022.html * https://www.suse.com/security/cve/CVE-2026-43023.html * https://www.suse.com/security/cve/CVE-2026-43024.html * https://www.suse.com/security/cve/CVE-2026-43028.html * https://www.suse.com/security/cve/CVE-2026-43034.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43049.html * https://www.suse.com/security/cve/CVE-2026-43053.html * https://www.suse.com/security/cve/CVE-2026-43074.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43079.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43081.html * https://www.suse.com/security/cve/CVE-2026-43083.html * https://www.suse.com/security/cve/CVE-2026-43085.html * https://www.suse.com/security/cve/CVE-2026-43086.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43094.html * https://www.suse.com/security/cve/CVE-2026-43101.html * https://www.suse.com/security/cve/CVE-2026-43107.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43119.html * https://www.suse.com/security/cve/CVE-2026-43128.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43158.html * https://www.suse.com/security/cve/CVE-2026-43171.html * https://www.suse.com/security/cve/CVE-2026-43187.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43238.html * https://www.suse.com/security/cve/CVE-2026-43239.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43303.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43339.html * https://www.suse.com/security/cve/CVE-2026-43345.html * https://www.suse.com/security/cve/CVE-2026-43405.html * https://www.suse.com/security/cve/CVE-2026-43420.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43469.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43491.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45838.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45841.html * https://www.suse.com/security/cve/CVE-2026-45848.html * https://www.suse.com/security/cve/CVE-2026-45862.html * https://www.suse.com/security/cve/CVE-2026-45870.html * https://www.suse.com/security/cve/CVE-2026-45891.html * https://www.suse.com/security/cve/CVE-2026-45894.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45940.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45961.html * https://www.suse.com/security/cve/CVE-2026-45964.html * https://www.suse.com/security/cve/CVE-2026-45965.html * https://www.suse.com/security/cve/CVE-2026-45974.html * https://www.suse.com/security/cve/CVE-2026-45985.html * https://www.suse.com/security/cve/CVE-2026-46005.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46053.html * https://www.suse.com/security/cve/CVE-2026-46063.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46071.html * https://www.suse.com/security/cve/CVE-2026-46076.html * https://www.suse.com/security/cve/CVE-2026-46101.html * https://www.suse.com/security/cve/CVE-2026-46112.html * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-46119.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46123.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-46160.html * https://www.suse.com/security/cve/CVE-2026-46162.html * https://www.suse.com/security/cve/CVE-2026-46172.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46185.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46214.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46244.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46259.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46273.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46289.html * https://www.suse.com/security/cve/CVE-2026-46291.html * https://www.suse.com/security/cve/CVE-2026-46315.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52908.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53052.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53122.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53138.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53266.html * https://www.suse.com/security/cve/CVE-2026-53281.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1236743 * https://bugzilla.suse.com/show_bug.cgi?id=1255029 * https://bugzilla.suse.com/show_bug.cgi?id=1256668 * https://bugzilla.suse.com/show_bug.cgi?id=1259764 * https://bugzilla.suse.com/show_bug.cgi?id=1261256 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262085 * https://bugzilla.suse.com/show_bug.cgi?id=1262392 * https://bugzilla.suse.com/show_bug.cgi?id=1262617 * https://bugzilla.suse.com/show_bug.cgi?id=1262618 * https://bugzilla.suse.com/show_bug.cgi?id=1262620 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1262748 * https://bugzilla.suse.com/show_bug.cgi?id=1262798 * https://bugzilla.suse.com/show_bug.cgi?id=1262993 * https://bugzilla.suse.com/show_bug.cgi?id=1263057 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263124 * https://bugzilla.suse.com/show_bug.cgi?id=1263137 * https://bugzilla.suse.com/show_bug.cgi?id=1263178 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263568 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263578 * https://bugzilla.suse.com/show_bug.cgi?id=1263581 * https://bugzilla.suse.com/show_bug.cgi?id=1263879 * https://bugzilla.suse.com/show_bug.cgi?id=1263880 * https://bugzilla.suse.com/show_bug.cgi?id=1263930 * https://bugzilla.suse.com/show_bug.cgi?id=1263934 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1263998 * https://bugzilla.suse.com/show_bug.cgi?id=1264001 * https://bugzilla.suse.com/show_bug.cgi?id=1264015 * https://bugzilla.suse.com/show_bug.cgi?id=1264045 * https://bugzilla.suse.com/show_bug.cgi?id=1264076 * https://bugzilla.suse.com/show_bug.cgi?id=1264080 * https://bugzilla.suse.com/show_bug.cgi?id=1264084 * https://bugzilla.suse.com/show_bug.cgi?id=1264116 * https://bugzilla.suse.com/show_bug.cgi?id=1264137 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1264228 * https://bugzilla.suse.com/show_bug.cgi?id=1264230 * https://bugzilla.suse.com/show_bug.cgi?id=1264231 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264239 * https://bugzilla.suse.com/show_bug.cgi?id=1264241 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264258 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264263 * https://bugzilla.suse.com/show_bug.cgi?id=1264266 * https://bugzilla.suse.com/show_bug.cgi?id=1264286 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264320 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264444 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264470 * https://bugzilla.suse.com/show_bug.cgi?id=1264549 * https://bugzilla.suse.com/show_bug.cgi?id=1264561 * https://bugzilla.suse.com/show_bug.cgi?id=1264562 * https://bugzilla.suse.com/show_bug.cgi?id=1264595 * https://bugzilla.suse.com/show_bug.cgi?id=1264603 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1264612 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264741 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1264763 * https://bugzilla.suse.com/show_bug.cgi?id=1264814 * https://bugzilla.suse.com/show_bug.cgi?id=1264974 * https://bugzilla.suse.com/show_bug.cgi?id=1265103 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265143 * https://bugzilla.suse.com/show_bug.cgi?id=1265211 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265628 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1266290 * https://bugzilla.suse.com/show_bug.cgi?id=1266390 * https://bugzilla.suse.com/show_bug.cgi?id=1266396 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266698 * https://bugzilla.suse.com/show_bug.cgi?id=1266700 * https://bugzilla.suse.com/show_bug.cgi?id=1266704 * https://bugzilla.suse.com/show_bug.cgi?id=1266705 * https://bugzilla.suse.com/show_bug.cgi?id=1266717 * https://bugzilla.suse.com/show_bug.cgi?id=1266734 * https://bugzilla.suse.com/show_bug.cgi?id=1266830 * https://bugzilla.suse.com/show_bug.cgi?id=1266840 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266878 * https://bugzilla.suse.com/show_bug.cgi?id=1266895 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266903 * https://bugzilla.suse.com/show_bug.cgi?id=1266916 * https://bugzilla.suse.com/show_bug.cgi?id=1266922 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266933 * https://bugzilla.suse.com/show_bug.cgi?id=1267208 * https://bugzilla.suse.com/show_bug.cgi?id=1267228 * https://bugzilla.suse.com/show_bug.cgi?id=1267251 * https://bugzilla.suse.com/show_bug.cgi?id=1267361 * https://bugzilla.suse.com/show_bug.cgi?id=1267365 * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267387 * https://bugzilla.suse.com/show_bug.cgi?id=1267427 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267431 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267582 * https://bugzilla.suse.com/show_bug.cgi?id=1267591 * https://bugzilla.suse.com/show_bug.cgi?id=1267621 * https://bugzilla.suse.com/show_bug.cgi?id=1267624 * https://bugzilla.suse.com/show_bug.cgi?id=1267628 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267640 * https://bugzilla.suse.com/show_bug.cgi?id=1267651 * https://bugzilla.suse.com/show_bug.cgi?id=1267654 * https://bugzilla.suse.com/show_bug.cgi?id=1267682 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267685 * https://bugzilla.suse.com/show_bug.cgi?id=1267697 * https://bugzilla.suse.com/show_bug.cgi?id=1267717 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267744 * https://bugzilla.suse.com/show_bug.cgi?id=1267816 * https://bugzilla.suse.com/show_bug.cgi?id=1267825 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267937 * https://bugzilla.suse.com/show_bug.cgi?id=1267953 * https://bugzilla.suse.com/show_bug.cgi?id=1267966 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1268159 * https://bugzilla.suse.com/show_bug.cgi?id=1268237 * https://bugzilla.suse.com/show_bug.cgi?id=1268307 * https://bugzilla.suse.com/show_bug.cgi?id=1268335 * https://bugzilla.suse.com/show_bug.cgi?id=1268428 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1268661 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269136 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269199 * https://bugzilla.suse.com/show_bug.cgi?id=1269281 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269314 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269418 * https://bugzilla.suse.com/show_bug.cgi?id=1269493 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269519 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269617 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269798 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1269884 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 * https://jira.suse.com/browse/PED-15880 * https://jira.suse.com/browse/PED-16303 * https://jira.suse.com/browse/PED-16305 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:30:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 08:30:14 -0000 Subject: SUSE-SU-2026:2804-1: important: Security update for kubevirt Message-ID: <178358581484.683.2530699627460074655@aaee731399ed> # Security update for kubevirt Announcement ID: SUSE-SU-2026:2804-1 Release Date: 2026-07-08T19:35:34Z Rating: important References: * bsc#1256434 * bsc#1262265 * bsc#1266733 Cross-References: * CVE-2025-14525 * CVE-2026-35469 * CVE-2026-9804 CVSS scores: * CVE-2025-14525 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-14525 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-14525 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-35469 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-35469 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35469 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-35469 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9804 ( SUSE ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9804 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for kubevirt fixes the following issues: * CVE-2026-9804: Symlink escape in the VMExport dir handler let an attacker controlling an exported PVC read sensitive files (TLS keys, tokens, service- account creds) from the exporter pod. (bsc#1266733) * CVE-2025-14525: A VM reporting many guest-internal interfaces via the guest agent could flood VMI status and fill etcd (denial of service). Caps reported interfaces at 10. (bsc#1256434) * CVE-2026-35469: resource-exhaustion in the SPDY/3 protocol implementation of github.com/moby/spdystream. (GHSA-pc3f-x583-g7j2,bsc#1262265) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2804=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-virtctl-1.7.4-150700.3.27.1 * kubevirt-virtctl-debuginfo-1.7.4-150700.3.27.1 * kubevirt-manifests-1.7.4-150700.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14525.html * https://www.suse.com/security/cve/CVE-2026-35469.html * https://www.suse.com/security/cve/CVE-2026-9804.html * https://bugzilla.suse.com/show_bug.cgi?id=1256434 * https://bugzilla.suse.com/show_bug.cgi?id=1262265 * https://bugzilla.suse.com/show_bug.cgi?id=1266733 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:30:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 08:30:22 -0000 Subject: SUSE-SU-2026:2803-1: important: Security update for dracut Message-ID: <178358582232.683.12938055667698663821@aaee731399ed> # Security update for dracut Announcement ID: SUSE-SU-2026:2803-1 Release Date: 2026-07-08T19:31:32Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.565.g682306ec5: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2803=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2803=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-2803=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2803=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * dracut-tools-059+suse.565.g682306ec5-150600.3.29.1 * dracut-extra-059+suse.565.g682306ec5-150600.3.29.1 * dracut-ima-059+suse.565.g682306ec5-150600.3.29.1 * dracut-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-fips-059+suse.565.g682306ec5-150600.3.29.1 * dracut-mkinitrd-deprecated-059+suse.565.g682306ec5-150600.3.29.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (ppc64le x86_64) * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-mkinitrd-deprecated-059+suse.565.g682306ec5-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dracut-ima-059+suse.565.g682306ec5-150600.3.29.1 * dracut-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-fips-059+suse.565.g682306ec5-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dracut-ima-059+suse.565.g682306ec5-150600.3.29.1 * dracut-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debuginfo-059+suse.565.g682306ec5-150600.3.29.1 * dracut-debugsource-059+suse.565.g682306ec5-150600.3.29.1 * dracut-fips-059+suse.565.g682306ec5-150600.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:30:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 08:30:57 -0000 Subject: SUSE-SU-2026:2802-1: important: Security update for netty, netty-tcnative Message-ID: <178358585794.683.17486454914556976320@aaee731399ed> # Security update for netty, netty-tcnative Announcement ID: SUSE-SU-2026:2802-1 Release Date: 2026-07-08T19:06:45Z Rating: important References: * bsc#1268165 * bsc#1268169 * bsc#1268170 * bsc#1268244 * bsc#1268246 * bsc#1268247 * bsc#1268248 * bsc#1268249 * bsc#1268250 * bsc#1268251 * bsc#1268252 * bsc#1268255 * bsc#1268257 * bsc#1268258 * bsc#1268259 * bsc#1268260 * bsc#1268261 * bsc#1268262 Cross-References: * CVE-2026-44249 * CVE-2026-44250 * CVE-2026-44890 * CVE-2026-44893 * CVE-2026-45416 * CVE-2026-45536 * CVE-2026-45673 * CVE-2026-45674 * CVE-2026-46340 * CVE-2026-47244 * CVE-2026-47691 * CVE-2026-48006 * CVE-2026-48043 * CVE-2026-48059 * CVE-2026-50010 * CVE-2026-50011 * CVE-2026-50020 * CVE-2026-50560 CVSS scores: * CVE-2026-44249 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44249 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44249 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44249 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44250 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44250 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44250 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44250 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44890 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44890 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44890 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44890 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44893 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44893 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45416 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45416 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45416 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45416 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45536 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45536 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45673 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N * CVE-2026-45673 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-45673 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N * CVE-2026-45674 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-45674 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-45674 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-45674 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-45674 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-46340 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46340 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46340 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46340 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47244 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-47244 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47244 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47691 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-47691 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-47691 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-47691 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-47691 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-48006 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48006 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48006 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48043 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48043 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48043 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48043 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48043 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48059 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48059 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50010 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-50010 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50010 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50010 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50011 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-50011 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50011 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50020 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-50020 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-50020 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-50560 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-50560 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-50560 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50560 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for netty, netty-tcnative fixes the following issue This update for netty, netty-tcnative fixes the following issues Upgrade netty to upstream version 4.1.135, netty-tcnative to upstream version 2.0.79: * CVE-2026-44249: IPv6 Subnet Filter Bypass via Incorrect Comparator Masking (bsc#1268165). * CVE-2026-44250: Memory Exhaustion in RedisArrayAggregator due to Deeply Nested Arrays (bsc#1268169). * CVE-2026-44890: Unbounded Direct Memory Consumption in RedisDecoder (bsc#1268170). * CVE-2026-44893: netty-codec-haproxy: Denial of Service via malformed HAProxy message (bsc#1268244). * CVE-2026-45416: SNI handler pre-allocates up to 16 MiB from nine attacker bytes (bsc#1268246). * CVE-2026-45536: Unix-socket fd receive leaks descriptors when peer sends two at once (bsc#1268247). * CVE-2026-45673: netty-resolver-dns: DNS Cache Poisoning via predictable transaction IDs (bsc#1268248). * CVE-2026-45674: DNS Cache Poisoning via Missing Bailiwick Checks in CNAME Records (bsc#1268249). * CVE-2026-46340: netty-transport-sctp: Denial of Service due to unbounded memory growth from SctpMessage fragments (bsc#1268250). * CVE-2026-47244: HTTP/2: Advertised MAX_CONCURRENT_STREAMS not enforced (bsc#1268251). * CVE-2026-47691: Insufficient Bailiwick Validation for NS Records (bsc#1268252). * CVE-2026-48006: netty-codec-redis: Netty's Lack of Lifecycle Cleanup Leads to Pooled ByteBuf Leak in RedisArrayAggregator (bsc#1268255). * CVE-2026-48043: netty-codec-http2: Denial of Service due to resource leak (bsc#1268257). * CVE-2026-48059: netty-codec-haproxy: Denial of Service via memory leak from crafted PROXY protocol headers (bsc#1268258). * CVE-2026-50010: Wrapping plain trust manager silently disables hostname verification (bsc#1268259). * CVE-2026-50011: Unbounded pre-allocation in RedisArrayAggregator from RESP array length (bsc#1268260). * CVE-2026-50020: HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted (bsc#1268261). * CVE-2026-50560: Netty susceptible to HTTP/2 Reset Attack with different on- the-wire signature (bsc#1268262). Changes: * MQTT: Allow MQTT 5 CONNECT with password only * ChannelInitializer: correct misleading comment on exceptionCaught route * HTTP/2: Parse request-target path like Vert.x (4.1 backport) * HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted * IpSubnetFilter: Correctly handle ipv6 * Configurable bound on RedisArrayAggregator * Redis: Limit decoded length * DNS: Ensure query id is not predictible * Wrapping plain trust manager silently disables hostname verification * MQTT: Reject malformed no-payload packets with non-zero Remaining Length * HAProxy: Reject HAProxyMessages with malformated TLV and not leak memory * SSL: Use sane defaults as limits for the client hello length and timeout * DNS: Only cache CNAME if part of the queried domain * HTTP/2: Enforce max concurrent streams for misbehaving clients * Dns: Insufficient Bailiwick Validation for NS Records * HTTP2: DelegatingDecompressorFrameListener must release memory in all cases * Pass maxAllocation to Brotli and Zstd decoders * HTTP/2: Treat clients MAX_HEADER_LIST_SIZE as advisory * Add maxWindowLog parameter to ZstdDecoder to bound memory allocation * HAProxy: Fix ByteBuf leak when parsing nested SSL TLVs * Epoll / Kqueue: Correctly handle receive of FD * SCTP: Limit the number of inflight incomplete SCTP messages and the number of fragments * Redis: Correctly release incomplete message on removal when using RedisArrayAggregator * Redis: Limit the maximum number of nested arrays * HTTP: Re-add constructor to HttpProxyHandler that was removed by mistake * Marshalling: Explicit document security requirements * Pin HTTP/RTSP version + method normalization to Locale.US * Adaptive: Fix concurrency issue in adaptive allocator * Pin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US * Remove dead native declarations * Avoid re-parsing openssl key material with non-cached provider * IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 * Resolve all localhost addresses without querying DNS servers * HTTP2: Use 100 as default max concurrent streams setting * Route synchronous onLookupComplete exceptions via fireExceptionCaught * Fix MQTT decoder size check after variable header replay ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2802=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2802=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2802=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2802=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2802=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2802=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2802=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2802=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2802=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2802=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2802=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2802=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * netty-javadoc-4.1.135-150200.4.50.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-4.1.135-150200.4.50.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * netty-tcnative-debugsource-2.0.79-150200.3.45.1 * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * netty-tcnative-2.0.79-150200.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * netty-tcnative-2.0.79-150200.3.45.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44249.html * https://www.suse.com/security/cve/CVE-2026-44250.html * https://www.suse.com/security/cve/CVE-2026-44890.html * https://www.suse.com/security/cve/CVE-2026-44893.html * https://www.suse.com/security/cve/CVE-2026-45416.html * https://www.suse.com/security/cve/CVE-2026-45536.html * https://www.suse.com/security/cve/CVE-2026-45673.html * https://www.suse.com/security/cve/CVE-2026-45674.html * https://www.suse.com/security/cve/CVE-2026-46340.html * https://www.suse.com/security/cve/CVE-2026-47244.html * https://www.suse.com/security/cve/CVE-2026-47691.html * https://www.suse.com/security/cve/CVE-2026-48006.html * https://www.suse.com/security/cve/CVE-2026-48043.html * https://www.suse.com/security/cve/CVE-2026-48059.html * https://www.suse.com/security/cve/CVE-2026-50010.html * https://www.suse.com/security/cve/CVE-2026-50011.html * https://www.suse.com/security/cve/CVE-2026-50020.html * https://www.suse.com/security/cve/CVE-2026-50560.html * https://bugzilla.suse.com/show_bug.cgi?id=1268165 * https://bugzilla.suse.com/show_bug.cgi?id=1268169 * https://bugzilla.suse.com/show_bug.cgi?id=1268170 * https://bugzilla.suse.com/show_bug.cgi?id=1268244 * https://bugzilla.suse.com/show_bug.cgi?id=1268246 * https://bugzilla.suse.com/show_bug.cgi?id=1268247 * https://bugzilla.suse.com/show_bug.cgi?id=1268248 * https://bugzilla.suse.com/show_bug.cgi?id=1268249 * https://bugzilla.suse.com/show_bug.cgi?id=1268250 * https://bugzilla.suse.com/show_bug.cgi?id=1268251 * https://bugzilla.suse.com/show_bug.cgi?id=1268252 * https://bugzilla.suse.com/show_bug.cgi?id=1268255 * https://bugzilla.suse.com/show_bug.cgi?id=1268257 * https://bugzilla.suse.com/show_bug.cgi?id=1268258 * https://bugzilla.suse.com/show_bug.cgi?id=1268259 * https://bugzilla.suse.com/show_bug.cgi?id=1268260 * https://bugzilla.suse.com/show_bug.cgi?id=1268261 * https://bugzilla.suse.com/show_bug.cgi?id=1268262 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 08:31:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 08:31:12 -0000 Subject: SUSE-SU-2026:2801-1: important: Security update for jackson-annotations, jackson-bom, jackson-core, jackson-databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent Message-ID: <178358587250.683.7515958594086102546@aaee731399ed> # Security update for jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent Announcement ID: SUSE-SU-2026:2801-1 Release Date: 2026-07-08T19:05:27Z Rating: important References: * bsc#1268603 * bsc#1268897 * bsc#1268898 * bsc#1268899 * bsc#1268902 Cross-References: * CVE-2026-54512 * CVE-2026-54513 * CVE-2026-54514 * CVE-2026-54515 CVSS scores: * CVE-2026-54512 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54512 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54513 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54514 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54515 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-54515 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for jackson-annotations, jackson-bom, jackson-core, jackson- databind, jackson-dataformats-binary, jackson-modules-base, jackson-parent fixes the following issues * CVE-2026-54512: jackson-databind has a PolymorphicTypeValidator bypass via generic type parameters that allows arbitrary class instantiation (bsc#1268897). * CVE-2026-54513: jackson-databind: array subtype allowlist bypass in BasicPolymorphicTypeValidator (bsc#1268898). * CVE-2026-54514: jackson-databind: InetSocketAddress deserialization triggers eager DNS resolution (bsc#1268899). * CVE-2026-54515: jackson-databindi: case-insensitive deserialization bypasses per-property @JsonIgnoreProperties (bsc#1268902). * jackson-core: document length constraint bypass in blocking, async, and DataInput parsers (bsc#1268603). Changes for jackson-annotations: * Update to 2.18.8 * No changes since 2.17.3 Changes for jackson-bom: * Update to 2.18.8 * Changes * # 68: Remove 'junit' 4.x dependency from 'jackson-base' 2.18.x to help junit5 migration * 'base/pom.xml' now creates '${project.version.underscore}' for "cleansed" version of '${project.version}' Changes for jackson-core: * Update to 2.18.8 * Changes of 2.18.8 * # 1611: Apply number-length validator on streaming integer path of async parser * Changes of 2.18.7 * # 1570: Fail parsing from 'DataInput' if 'StreamReadConstraints .getMaxDocumentLength()' set (bsc#1268603, GHSA-2m67-wjpj-xhg9) * # 1600: Rework 3rd party licenses in jar * # 1602: 'UTF8DataInputJsonParser' needs to enforce 'StreamReadConstraints.maxNameLength' limit * Changes of 2.18.6 * # 1512: Number-parsing fix for 'UTF8DataInputJsonParser' * # 1548: 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer * # 1555: Enforce 'StreamReadConstraints.maxNumberLength' for non-blocking (async) parser * Changes of 2.18.5 * # 1433: 'JsonParser#getNumberType()' throws 'JsonParseException' when the current token is non-numeric instead of returning null * # 1446: Invalid package reference to "java.lang.foreign" from 'com.fasterxml.jackson.core:jackson-core' (from 'FastDoubleParser') * Changes of 2.18.3 * # 1391: Fix issue where the parser can read back old number state when parsing later numbers * # 1397: Jackson changes additional values to infinite in case of special JSON structures and existing infinite values * # 1398: Fix issue that feature COMBINE_UNICODE_SURROGATES_IN_UTF8 doesn't work when custom characterEscape is used * Changes of 2.18.2 * # 1359: Non-surrogate characters being incorrectly combined when 'JsonWriteFeature.COMBINE_UNICODE_SURROGATES_IN_UTF8' is enabled * Changes of 2.18.1 * # 1353: Use fastdoubleparser 1.0.90 * Changes of 2.18. * # 223: 'UTF8JsonGenerator' writes supplementary characters as a surrogate pair: should use 4-byte encoding * # 1230: Improve performance of 'float' and 'double' parsing from 'TextBuffer' * # 1251: 'InternCache' replace synchronized with 'ReentrantLock' * the cache size limit is no longer strictly enforced for performance reasons but we should never go far about the limit * # 1252: 'ThreadLocalBufferManager' replace synchronized with 'ReentrantLock' * # 1257: Increase InternCache default max size from 100 to 200 * # 1262: Add diagnostic method 'pooledCount()' in 'RecyclerPool' * # 1264: Rename shaded 'ch.randelshofer:fastdoubleparser' classes to prevent use by downstream consumers * # 1271: Deprecate 'LockFreePool' implementation in 2.18 (remove from 3.0) * # 1274: 'NUL'-corrupted keys, values on JSON serialization * # 1277: Add back Java 22 optimisation in FastDoubleParser * # 1284: Optimize 'JsonParser.getDoubleValue()/getFloatValue() /getDecimalValue()' to avoid String allocation * # 1305: Make helper methods of 'WriterBasedJsonGenerator' non-final to allow overriding * # 1310: Add new 'StreamReadConstraints' ('maxTokenCount') to limit maximum number of Tokens allowed per document# * # 1331: Update to FastDoubleParser v1.0.1 to fix 'BigDecimal' decoding proble Changes for jackson-databind: * Update to 2.18.8 * Changes of 2.18.8 * # 5950: Improve 'UUIDeserializer' error handling * # 5951: Improve 'InetSocketAddress' deserialization (bsc#1268899, CVE-2026-54514) * # 5969: '@JsonView' by-passed for some "setterless" creator properties * # 5971: '@JsonView' by-passed for unwrapped creator parameters * # 5974: '@JsonIgnore' on Record property ignored with 'PropertyNamingStrategy' * # 5981: 'BasicPolymorphicTypeValidator' setting 'allowIfSubTypeIsArray()' should validate element type (bsc#1268898, CVE-2026-54513) * # 5988: 'PolymorphicTypeValidator' needs to validate generic type parameters too (bsc#1268897, CVE-2026-54512) * # 5993: 'UPPER_SNAKE_CASE' / 'LOWER_CASE' 'NamingStrategyImpls' fold case using JVM default locale (Turkish-I bug) * Changes of 2.18.4 * # 4628: '@JsonIgnore' and '@JsonProperty.access=READ_ONLY' on Record property ignored for deserialization * # 5049: Duplicate creator property "b" (index 0 vs 1) on simple java record * Changes of 2.18.3 * # 4444: The 'KeyDeserializer' specified in the class with '@JsonDeserialize(keyUsing = ...)' is overwritten by the 'KeyDeserializer' specified in the 'ObjectMapper'. * # 4827: Subclassed Throwable deserialization fails since v2.18.0 - no creator index for property 'cause' * # 4844: Fix wrapped array handling wrt 'null' by 'StdDeserializer' * # 4848: Avoid type pollution in 'StringCollectionDeserializer' * # 4860: 'ConstructorDetector.USE_PROPERTIES_BASED' does not work with multiple constructors since 2.18 * # 4878: When serializing a Map via Converter(StdDelegatingSerializer), a NullPointerException is thrown due to missing key serializer * # 4908: Deserialization behavior change with @JsonCreator and @ConstructorProperties between 2.17 and 2.18 * # 4917: 'BigDecimal' deserialization issue when using '@JsonCreator' * # 4920: Creator properties are ignored on abstract types when collecting bean properties, breaking AsExternalTypeDeserializer * # 4922: Failing '@JsonMerge' with a custom Map * # 4932: Conversion of 'MissingNode' throws 'JsonProcessingException' * Changes of 2.18.2 * # 4733: Wrong serialization of Type Ids for certain types of Enum values * # 4742: Deserialization with Builder, External type id, '@JsonCreator' failing * # 4777: 'StdValueInstantiator.withArgsCreator' is now set for creators with no arguments * # 4783 Possibly wrong behavior of @JsonMerge * # 4787: Wrong 'String.format()' in 'StdDelegatingDeserializer' hides actual error * # 4788: 'EnumFeature.WRITE_ENUMS_TO_LOWERCASE' overrides '@JsonProperty' values * # 4790: Fix '@JsonAnySetter' issue with "setter" method (related to #4639) * # 4807: Improve 'FactoryBasedEnumDeserializer' to work better with XML module * # 4810: Deserialization using '@JsonCreator' with renamed property failing (since 2.18) * Changes of 2.18.1 * # 4508: Deserialized JsonAnySetter field in Kotlin data class is null * # 4639: @JsonAnySetter on field ignoring unrecognized properties if they are declared before the last recognized properties in JSON * # 4718: Should not fail on trying to serialize 'java.time.DateTimeException' * # 4724: Deserialization behavior change with Records, '@JsonCreator' and '@JsonValue' between 2.17 and 2.18 * # 4727: Eclipse having issues due'module-info' class "lost" on 2.18.0 jars * # 4741: When 'Include.NON_DEFAULT' setting is used on POJO, empty values are not included in json if default is 'null' * # 4749: Fixed a problem with 'StdDelegatingSerializer#serializeWithType' looking up the serializer with the wrong argument * Changes of 2.18.0 * # 562: Allow '@JsonAnySetter' to flow through Creators * # 806: Problem with 'NamingStrategy', creator methods with implicit names * # 2977: Incompatible 'FAIL_ON_MISSING_PRIMITIVE_PROPERTIES' and field level '@JsonProperty' * # 3120: Return 'ListIterator' from 'ArrayNode.elements()' * # 3241: 'constructorDetector' seems to invalidate 'defaultSetterInfo' for nullability * # 3439: Java Record '@JsonAnySetter' value is null after deserialization * # 4085: '@JsonView' does not work on class-level for records * # 4119: Exception when deserialization uses a record with a constructor property with 'access=READ_ONLY' * # 4356: 'BeanDeserializerModifier::updateBuilder()' doesn't work for beans with Creator methods * # 4407: 'null' type id handling does not work with 'writeTypePrefix()' * # 4452: '@JsonProperty' not serializing field names properly on '@JsonCreator' in Record * # 4453: Allow JSON Integer to deserialize into a single-arg constructor of parameter type 'double' * # 4456: Rework locking in 'DeserializerCache' * # 4458: Rework synchronized block from 'BeanDeserializerBase' * # 4464: When 'Include.NON_DEFAULT' setting is used, 'isEmpty()' method is not called on the serializer * # 4472: Rework synchronized block in 'TypeDeserializerBase' * # 4483: Remove 'final' on method BeanSerializer.serialize() * # 4515: Rewrite Bean Property Introspection logic in Jackson 2.x * # 4545: Unexpected deserialization behavior with '@JsonCreator', '@JsonProperty' and javac '-parameters' * # 4570: Deprecate 'ObjectMapper.canDeserialize()'/'ObjectMapper .canSerialize()' * # 4580: Add 'MapperFeature .SORT_CREATOR_PROPERTIES_BY_DECLARATION_ORDER' to use Creator properties' declaration order for sorting * # 4584: Provide extension point for detecting "primary" Constructor for Kotlin (and similar) data classes * # 4602: Possible wrong use of _arrayDelegateDeserializer in BeanDeserializerBase::deserializeFromObjectUsingNonDefault() * # 4617: Record property serialization order not preserved * # 4626: '@JsonIgnore' on Record property ignored for deserialization, if there is getter override * # 4630: '@JsonIncludeProperties', '@JsonIgnoreProperties' ignored when serializing Records, if there is getter override * # 4634: '@JsonAnySetter' not working when annotated on both constructor parameter & field * # 4678: Java records don't serialize with 'MapperFeature .REQUIRE_SETTERS_FOR_GETTERS' * # 4688: Should allow deserializing with no-arg '@JsonCreator(mode = DELEGATING)' * # 4694: Deserializing 'BigDecimal' with large number of decimals result in incorrect value * # 4699: Add extra 'writeNumber()' method in 'TokenBuffer' * # 4709: Add 'JacksonCollectors' with 'toArrayNode()' implementation * Fix #5962: Case-insensitive deserialization may use wrong @JsonIgnoreProperties (bsc#1268902, CVE-2026-54515) * Fix "Not fully interpolated version" error with Maven 4 Changes for jackson-dataformats-binary: * Update to 2.18.8 * Changes of 2.18.8 * # 696: (ion) Incomplete number length validation in Ion decoder (for 'BigDecimal' and/or 'BigInteger') * Changes of 2.18.6 * # 645: (avro) Remove use of Avro 'Schema.Parser() .setValidate()' to allow use of Avro core 1.12.1 (2.x) * # 649: (cbor, smile) 'StreamReadConstraints.maxDocumentLength' not checked when creating parser with fixed buffer * # 651: (smile) Ensure Smile backend supports 'StreamReadConstraints.maxTokenCount' * # 652: (cbor) Ensure CBOR backend supports * Minor fix to 'ProtobufGenerator._reportEnumError()' helper method * Changes of 2.18.5 * # 599: (cbor) Unable to deserialize stringref-enabled CBOR with ignored properties * # 623: (ion) Upgrade 'ion-java' dep to 1.11.11 (from 1.11.10) * Changes of 2.18.4 * # 569: (ion) 'IonParser' fails to parse some 'long' values saying they are out of range when they are not * # 584: (protobuf) Missing 'JsonToken.END_OBJECT' for nested Protobuf Objects * (ion) Upgrade 'ion-java' to 1.11.10 (from 1.11.9) * Changes of 2.18.3 * # 541: (cbor, protobuf, smile) 'SmileParser.getValueAsString()' FIELD_NAME bug * Changes of 2.18.1 * # 518: Should not read past end for CBOR string values * Changes of 2.18.0 * # 167: (avro) Incompatibility with Avro >=1.9.0 (upgrade to Avro 1.11.3) * # 484: (protobuf) Rework synchronization in 'ProtobufMapper' * # 494: (avro) Avro Schema generation: allow mapping Java Enum properties to Avro String values * # 508: (avro) Ignore 'specificData' field on serialization * # 509: IonValueMapper.builder() not implemented, does not register modules * (ion) Upgrade 'ion-java' to 1.11.9 (from 1.11.8) value Changes for jackson-modules-base: * Upgrade to 2.18.8 * No changes since 2.18.0 * Changes of 2.18.0 * # 233: (jaxb) Tolerate JAX-RS 2.2 in jackson-module-jaxb-annotations so that it can be deployed in Liberty alongside features which use 2.2 * # 248: (android-record) jClass annotations and polymorphic types are ignored when deserializing Android Record fields * # 251: (android-record) Constructor is not recognized when a record uses both arrays and generic types Changes for jackson-parent: * Update to 2.18.4 * Changes of 2.18.4 * Update to latest 'oss-parent' (69) * Changes of 2.18.3 * Update to latest 'oss-parent' (68) * Switch to publishing via Sonatype Central Portal repo * Changes of 2.18.2 * Update to latest 'oss-parent' (66); future-proof for Sonatype Central Portal * Changes of 2.18.1 * # 15: Add override to downgrade 'moditect-maven-plugin' from 1.2.2 to 1.1.0 to work around Eclipse issues * Changes of 2.18 * Update to oss-parent 61 (plugin version updates) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2801=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2801=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2801=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2801=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2801=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2801=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2801=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2801=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2801=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2801=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * Basesystem Module 15-SP7 (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-core-2.18.8-150200.3.22.3 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-annotations-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * jackson-annotations-2.18.8-150200.3.22.3 * jackson-databind-2.18.8-150200.3.28.2 * jackson-core-2.18.8-150200.3.22.3 * jackson-dataformat-cbor-2.18.8-150200.3.21.3 * Development Tools Module 15-SP7 (noarch) * jackson-dataformat-cbor-2.18.8-150200.3.21.3 ## References: * https://www.suse.com/security/cve/CVE-2026-54512.html * https://www.suse.com/security/cve/CVE-2026-54513.html * https://www.suse.com/security/cve/CVE-2026-54514.html * https://www.suse.com/security/cve/CVE-2026-54515.html * https://bugzilla.suse.com/show_bug.cgi?id=1268603 * https://bugzilla.suse.com/show_bug.cgi?id=1268897 * https://bugzilla.suse.com/show_bug.cgi?id=1268898 * https://bugzilla.suse.com/show_bug.cgi?id=1268899 * https://bugzilla.suse.com/show_bug.cgi?id=1268902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 12:30:24 -0000 Subject: SUSE-SU-2026:2811-1: important: Security update for python-maturin Message-ID: <178360022459.699.8267224466727506449@5ed4f61072e9> # Security update for python-maturin Announcement ID: SUSE-SU-2026:2811-1 Release Date: 2026-07-09T06:25:49Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.6 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-maturin fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2811=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-maturin-1.4.0-150600.3.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 12:30:30 -0000 Subject: SUSE-SU-2026:2810-1: moderate: Security update for glib-networking Message-ID: <178360023088.699.11326260646641713407@5ed4f61072e9> # Security update for glib-networking Announcement ID: SUSE-SU-2026:2810-1 Release Date: 2026-07-09T06:14:47Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2810=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2810=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2810=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2810=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2810=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2810=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * glib-networking-64bit-2.70.1-150400.3.3.1 * glib-networking-64bit-debuginfo-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * glib-networking-32bit-debuginfo-2.70.1-150400.3.3.1 * glib-networking-32bit-2.70.1-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * glib-networking-lang-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * glib-networking-2.70.1-150400.3.3.1 * glib-networking-debuginfo-2.70.1-150400.3.3.1 * glib-networking-debugsource-2.70.1-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 12:30:41 -0000 Subject: SUSE-SU-2026:2809-1: moderate: Security update for systemd Message-ID: <178360024145.699.7863684309235364229@5ed4f61072e9> # Security update for systemd Announcement ID: SUSE-SU-2026:2809-1 Release Date: 2026-07-09T06:08:36Z Rating: moderate References: * bsc#1261400 * bsc#1261982 * bsc#1261983 * bsc#1267647 Cross-References: * CVE-2026-40226 CVSS scores: * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for systemd fixes the following issue Security issues fixed: * CVE-2026-40226: nspawn: escape-to-host via malformed optional config file (bsc#1261400). Other updates and bugfixes: * Import commit 37508f8ec1 (bsc#1267647). * Import commit c7530fbea3 (bsc#1261982 bsc#1261983). * Import commit 5c4ed461a7 (bsc#1261982). * Import commit 4b963df038 (bsc#1261983). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2809=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2809=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2809=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2809=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2809=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2809=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-mini-doc-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * libudev-mini1-249.17-150400.8.64.1 * nss-systemd-249.17-150400.8.64.1 * systemd-mini-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-mini-debuginfo-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libudev-mini1-debuginfo-249.17-150400.8.64.1 * systemd-portable-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libsystemd0-mini-debuginfo-249.17-150400.8.64.1 * systemd-experimental-249.17-150400.8.64.1 * systemd-testsuite-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-mini-devel-249.17-150400.8.64.1 * systemd-coredump-debuginfo-249.17-150400.8.64.1 * systemd-mini-container-debuginfo-249.17-150400.8.64.1 * systemd-network-debuginfo-249.17-150400.8.64.1 * systemd-mini-debuginfo-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * systemd-devel-249.17-150400.8.64.1 * nss-systemd-debuginfo-249.17-150400.8.64.1 * systemd-experimental-debuginfo-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * udev-mini-249.17-150400.8.64.1 * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * systemd-testsuite-debuginfo-249.17-150400.8.64.1 * systemd-mini-debugsource-249.17-150400.8.64.1 * systemd-mini-sysvinit-249.17-150400.8.64.1 * systemd-coredump-249.17-150400.8.64.1 * nss-myhostname-249.17-150400.8.64.1 * systemd-doc-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-mini-container-249.17-150400.8.64.1 * nss-myhostname-debuginfo-249.17-150400.8.64.1 * systemd-portable-debuginfo-249.17-150400.8.64.1 * libsystemd0-mini-249.17-150400.8.64.1 * systemd-network-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * openSUSE Leap 15.4 (x86_64) * nss-myhostname-32bit-debuginfo-249.17-150400.8.64.1 * libudev1-32bit-249.17-150400.8.64.1 * libudev1-32bit-debuginfo-249.17-150400.8.64.1 * nss-myhostname-32bit-249.17-150400.8.64.1 * systemd-32bit-249.17-150400.8.64.1 * systemd-32bit-debuginfo-249.17-150400.8.64.1 * libsystemd0-32bit-debuginfo-249.17-150400.8.64.1 * libsystemd0-32bit-249.17-150400.8.64.1 * openSUSE Leap 15.4 (aarch64_ilp32) * nss-myhostname-64bit-debuginfo-249.17-150400.8.64.1 * systemd-64bit-debuginfo-249.17-150400.8.64.1 * libudev1-64bit-249.17-150400.8.64.1 * systemd-64bit-249.17-150400.8.64.1 * nss-myhostname-64bit-249.17-150400.8.64.1 * libudev1-64bit-debuginfo-249.17-150400.8.64.1 * libsystemd0-64bit-249.17-150400.8.64.1 * libsystemd0-64bit-debuginfo-249.17-150400.8.64.1 * openSUSE Leap 15.4 (noarch) * systemd-lang-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * systemd-journal-remote-debuginfo-249.17-150400.8.64.1 * udev-249.17-150400.8.64.1 * systemd-sysvinit-249.17-150400.8.64.1 * systemd-container-249.17-150400.8.64.1 * systemd-debugsource-249.17-150400.8.64.1 * systemd-debuginfo-249.17-150400.8.64.1 * systemd-container-debuginfo-249.17-150400.8.64.1 * systemd-journal-remote-249.17-150400.8.64.1 * udev-debuginfo-249.17-150400.8.64.1 * libsystemd0-249.17-150400.8.64.1 * libudev1-debuginfo-249.17-150400.8.64.1 * libsystemd0-debuginfo-249.17-150400.8.64.1 * libudev1-249.17-150400.8.64.1 * systemd-249.17-150400.8.64.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40226.html * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 12:30:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 12:30:59 -0000 Subject: SUSE-SU-2026:2807-1: important: Security update for rust-keylime Message-ID: <178360025906.699.1232436425669330894@5ed4f61072e9> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:2807-1 Release Date: 2026-07-09T04:47:14Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for rust-keylime fixes the following issues * Update to version 0.2.9+49 * Update openssl to 0.10.81 * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl crate (bsc#1270614). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270699). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270842). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270999). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2807=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * rust-keylime-0.2.9+49-150500.3.19.1 * rust-keylime-debuginfo-0.2.9+49-150500.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 20:30:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 20:30:12 -0000 Subject: SUSE-SU-2026:2582-2: important: Security update for MozillaFirefox Message-ID: <178362901211.765.14062140743493064282@5ed4f61072e9> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:2582-2 Release Date: 2026-07-09T14:11:02Z Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: NOTE: This update was retracted as it contained incorrect provides/obsolets on mozilla-nss-certs. Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2582=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2582=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2582=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2582=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2582=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2582=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2582=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2582=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2582=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2582=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2582=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-debuginfo-140.12.0-150200.152.242.1 * MozillaFirefox-translations-common-140.12.0-150200.152.242.1 * MozillaFirefox-140.12.0-150200.152.242.1 * MozillaFirefox-debugsource-140.12.0-150200.152.242.1 * MozillaFirefox-translations-other-140.12.0-150200.152.242.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.242.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 9 20:31:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 09 Jul 2026 20:31:09 -0000 Subject: SUSE-SU-2026:2814-1: important: Security update for MozillaFirefox Message-ID: <178362906964.765.10973889133984437025@5ed4f61072e9> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:2814-1 Release Date: 2026-07-09T12:26:39Z Rating: important References: * bsc#1268071 * bsc#1269226 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: * Removed obsolete mozilla-nss-certs and recommends p11-kit-nss-trust (bsc#1269226) Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2814=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2814=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2814=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2814=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2814=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2814=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2814=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-other-140.12.0-150200.152.245.1 * MozillaFirefox-140.12.0-150200.152.245.1 * MozillaFirefox-debugsource-140.12.0-150200.152.245.1 * MozillaFirefox-debuginfo-140.12.0-150200.152.245.1 * MozillaFirefox-translations-common-140.12.0-150200.152.245.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-140.12.0-150200.152.245.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 * https://bugzilla.suse.com/show_bug.cgi?id=1269226 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:30:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:30:27 -0000 Subject: SUSE-SU-2026:2835-1: important: Security update for clamav Message-ID: <178367222742.944.11203165131806337179@530c474df1e7> # Security update for clamav Announcement ID: SUSE-SU-2026:2835-1 Release Date: 2026-07-09T19:13:18Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2835=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2835=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2835=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2835=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150600.18.28.1 * clamav-milter-1.5.3-150600.18.28.1 * clamav-debugsource-1.5.3-150600.18.28.1 * clamav-1.5.3-150600.18.28.1 * clamav-devel-1.5.3-150600.18.28.1 * libfreshclam4-debuginfo-1.5.3-150600.18.28.1 * libclamav12-1.5.3-150600.18.28.1 * libclamav12-debuginfo-1.5.3-150600.18.28.1 * clamav-milter-debuginfo-1.5.3-150600.18.28.1 * libclammspack0-debuginfo-1.5.3-150600.18.28.1 * libfreshclam4-1.5.3-150600.18.28.1 * clamav-debuginfo-1.5.3-150600.18.28.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.3-150600.18.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:30:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:30:46 -0000 Subject: SUSE-SU-2026:2834-1: important: Security update for clamav Message-ID: <178367224626.944.14139455072829739064@530c474df1e7> # Security update for clamav Announcement ID: SUSE-SU-2026:2834-1 Release Date: 2026-07-09T19:12:56Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2834=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2834=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2834=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2834=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2834=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2834=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libclammspack0-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * clamav-devel-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 * clamav-1.5.3-150400.13.8.1 * clamav-milter-1.5.3-150400.13.8.1 * clamav-milter-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:31:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:31:02 -0000 Subject: SUSE-SU-2026:2833-1: important: Security update for clamav Message-ID: <178367226238.944.562404057243915366@530c474df1e7> # Security update for clamav Announcement ID: SUSE-SU-2026:2833-1 Release Date: 2026-07-09T19:11:01Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2833=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2833=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * clamav-docs-html-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libclammspack0-debuginfo-1.5.3-3.56.1 * libfreshclam4-debuginfo-1.5.3-3.56.1 * clamav-devel-1.5.3-3.56.1 * clamav-debuginfo-1.5.3-3.56.1 * libclamav12-1.5.3-3.56.1 * clamav-milter-1.5.3-3.56.1 * libclamav12-debuginfo-1.5.3-3.56.1 * clamav-1.5.3-3.56.1 * clamav-debugsource-1.5.3-3.56.1 * clamav-milter-debuginfo-1.5.3-3.56.1 * libfreshclam4-1.5.3-3.56.1 * libclammspack0-1.5.3-3.56.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * clamav-docs-html-1.5.3-3.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:31:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:31:23 -0000 Subject: SUSE-SU-2026:2832-1: important: Security update for rustup Message-ID: <178367228393.944.1171808025028834320@530c474df1e7> # Security update for rustup Announcement ID: SUSE-SU-2026:2832-1 Release Date: 2026-07-09T19:02:15Z Rating: important References: * bsc#1203257 * bsc#1230032 * bsc#1243862 * bsc#1249008 * bsc#1270186 * bsc#1270521 * bsc#1270619 * bsc#1270644 * bsc#1270795 * bsc#1270870 * bsc#1270874 * bsc#1270989 Cross-References: * CVE-2024-12224 * CVE-2025-58160 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 10 vulnerabilities and has two security fixes can now be installed. ## Description: This update for rustup fixes the following issues Security issues: * CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270186). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270619). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270644). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270795). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270870). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270521). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270874). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270989). * rust-shlex: Multiple issues involving quote API ( RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032). Non security issue: * devel:languages:rust/rustup: Missing symlink for rust-analyzer (bsc#1203257). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2832=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2832=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2832=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2832=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 * Development Tools Module 15-SP7 (aarch64 x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 * openSUSE Leap 15.6 (aarch64 x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debugsource-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * rustup-1.28.2~0-150600.10.13.1 * rustup-debuginfo-1.28.2~0-150600.10.13.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1203257 * https://bugzilla.suse.com/show_bug.cgi?id=1230032 * https://bugzilla.suse.com/show_bug.cgi?id=1243862 * https://bugzilla.suse.com/show_bug.cgi?id=1249008 * https://bugzilla.suse.com/show_bug.cgi?id=1270186 * https://bugzilla.suse.com/show_bug.cgi?id=1270521 * https://bugzilla.suse.com/show_bug.cgi?id=1270619 * https://bugzilla.suse.com/show_bug.cgi?id=1270644 * https://bugzilla.suse.com/show_bug.cgi?id=1270795 * https://bugzilla.suse.com/show_bug.cgi?id=1270870 * https://bugzilla.suse.com/show_bug.cgi?id=1270874 * https://bugzilla.suse.com/show_bug.cgi?id=1270989 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:31:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:31:48 -0000 Subject: SUSE-SU-2026:2831-1: important: Security update for rustup Message-ID: <178367230877.944.800312328171909453@530c474df1e7> # Security update for rustup Announcement ID: SUSE-SU-2026:2831-1 Release Date: 2026-07-09T18:55:58Z Rating: important References: * bsc#1203257 * bsc#1230032 * bsc#1243862 * bsc#1249008 * bsc#1257902 * bsc#1270186 * bsc#1270521 * bsc#1270619 * bsc#1270644 * bsc#1270795 * bsc#1270870 * bsc#1270874 * bsc#1270989 Cross-References: * CVE-2024-12224 * CVE-2025-58160 * CVE-2026-25727 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 11 vulnerabilities and has two security fixes can now be installed. ## Description: This update for rustup fixes the following issues Security issues: * CVE-2024-12224: idna: idna accepts Punycode labels that do not produce any non-ASCII when decoded (bsc#1243862). * CVE-2025-58160: tracing-subscriber: Tracing log pollution (bsc#1249008). * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257902). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270186). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270619). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270644). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270795). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270870). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270521). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270874). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270989). * rust-shlex: Multiple issues involving quote API ( RUSTSEC-2024-0006, GHSA-r7qv-8r2h-pg27) (bsc#1230032). Non security issue: * devel:languages:rust/rustup: Missing symlink for rust-analyzer (bsc#1203257). Changes for rustup: * Completely drop openssl to prevent future security issues Update to version 1.28.2~0: * Deprecate native-tls as well * Enable HTTP/2 support for reqwest download backend * Emit tracing events from log facade calls * download: show Debug representation for errors * Avoid repeated globals in tracing events * Log original download errors immediately * feat(cli/rustup-mode): add aliases to `rustup component remove` * Switch flate2 to use the zlib-rs backend * Hardlink proxies if symlinks aren't reachable * Add powerpc64le-unknown-linux-musl support * Add toolchain_name to not installed bail msg * Warn about using curl * Drop workspace indirection * Fold download crate back into rustup * download: merge integration test files * chore(deps): lock file maintenance * Test CARGO environment replacement * Update CARGO env var if it is a rustup proxy * Tweak toolchain subcommand help text * Move toolchain and default commands first * show toolchain paths in rustup show -v output * refactor(cli/self-update): save allocations in `Nu::rcfiles()` * fix(cli/self-update)!: stop appending to `env.nu` due to deprecation * fix(cli/self-update): consider Windows paths in Nushell suggestions * refactor(cli/self-update): use `path add` in `env.nu` template * fix(cli/self-update): use interpolated string in `env.nu` template * Upgrade dependencies * docs(user-guide/environment-variables): document `RUSTUP_VERSION` * feat(rustup-init/sh): allow setting `RUSTUP_VERSION` during installation * feat(cli/self-update): allow setting `RUSTUP_VERSION` for arbitrary downgrades * feat(test/clitools): add `Config::expect_ok_ex_env()` * fix(errors)!: improve error messages for `RustupError::ToolchainNotInstalled` * Add set auto-install disable * Use `cursor: pointer` for copy button on website * fix(dist): refine suggestions about missing targets * Append Windows bin directory to PATH by default * Remove validation for custom toolchains when reading rust-toolchain.toml * document RUSTUP_AUTO_INSTALL * Fix build script `cargo` instructions Update to version 1.28.1~0: * dist(rustup-init/sh): update commit shasum * Update changelog for 1.28.1 * fix!(config): re-enable implicit toolchain installation in `Cfg::local_toolchain()` with optional opt-out * refactor(test/clitools): extract `Config::expect_err_env()` * Use relative symlinks when possible * docs: update CHANGELOG for v1.28.1 release * fix!(config): re-enable active toolchain installation in `Cfg::find_active_toolchain()` with optional opt-out * config: make Config::find_active_toolchain() async * Use terse output for rustup show active-toolchain * Use read_timeout for reqwest instead of timeout * test: turn set_current_dist_date() into a Config method * test: privatize clitools module * test: remove function wrappers for cmd() and env() * test: privatize mock module * test: move create_mock_dist_server() to Scenario::write_to() * test: move Release into dist * test: turn channel builders into constructors * test: move mock channel builders into dist * test: move arch consts into top-level module * test: turn build_*_installer() functions into constructors * test: move installer builders into mock module * test: privatize items in clitools * test: keep Config impl close to type definition * test: privatize dist module * test: privatize items in test::dist * test: inline short module topical_doc_data * Remove level of nesting in test module * Tweak SanitizedOutput style * docs: update `CHANGELOG` for v1.28.0 release * Have mocked cargo better adhere to cargo conventions * Do not append `EXE_SUFFIX` in `Config::cmd` * Add `TryFrom<Output>` for `SanitizedOutput` * refactor(test): replace `(before|after)_test_async()` with `TestProcess::_telemetry_guard` * style(rustup-init): reorganize imports * refactor(log): introduce `GlobalTelemetryGuard` * refactor(process): rename `TestProcess::_guard` to `_tracing_guard` * chore(deps): update opentelemetry * fix(deps): update rust crate windows-registry to 0.5.0 * refactor: improve binary suffix stripping * build: bump the codebase Language Edition to 2024 * style(cli/job): fix `unsafe-op-in-unsafe-fn` * style(cli/log): use precise capturing when necessary * chore: use unsafe versions of `(add|remove)_var()` * style: remove redundant `ref` keywords * style: partially migrate away from `if-let` * style: format sources with the 2024 Style Edition * chore: fix new `clippy` warnings * fix(deps): update rust crate pulldown-cmark to 0.13 * feat(rustup-init/sh): add env var to print arch detection result * refactor(component): reduce allocations in `ComponentPart::encode()` * refactor(component)!: extract `ComponentPartKind` * style(component): reduce right drift in `ComponentPart::decode()` * refactor(component)!: turn `ComponentPart`'s fields into named ones * fix(dist/prefix): normalize path separators in `REL_MANIFEST_DIR` * fix(component): normalize path separators during `ComponentPart::(en|de)code()` * Upgrade to rand 0.9 * fix(ci/doc): fix typo in renovate `datasource` * ci(doc): make `renovatebot` bump locked `mdbook` * ci(doc): pin `mdbook` to `0.4.43` * ci(schedule): run cron tasks more times per week * ci(schedule): promote to use the `stable` job list * ci(doc): fix stable build of `user-guide` * ci(linux): enable the full test suite for `aarch64-unknown-linux-gnu` * ci(linux): use public ARM64 Linux runners * ci(deploy-docs): merge with `test-docs` * ci(deploy-docs): enable on PR without uploads * ci(deploy-docs): build one book per workflow step * ci(deploy-docs): install `mdbook` with `install-action` * Change installation of dependencies for Aarch64 Dockerfile * Run Aarch64 jobs on PRs * Use ARM based runners for ARM CI targets * style: fix `clippy` warnings * docs(user-guide/components): add deprecation notice for `wasm32-wasi` * Update Windows dependencies * feat(cli/rustup-mode)!: simplify error message for `rustup show active- toolchain` * fix(cli/rustup-mode): make `rustup show active-toolchain` exit with `1` when none is active * fix(cli/rustup-mode): make `rustup default` exit with `1` when there's no default * fix(cli/rustup-mode)!: change `rustup doc --error_codes` to `--error-codes` * fix(deps): update rust crate itertools to 0.14 * fix(cli): align `rustup show`'s `--verbose` behavior with `rustup show active-toolchain` * feat(cli): show the toolchain path with `rustup show active-toolchain --verbose` * feat(test): accept more than one args in `for_host*!()` * fix(ci): fix installation of `cargo-all-features` * docs(user-guide/installation): update "General tips" * move deps around * fix(deps): update rust crate rustls-platform-verifier to 0.5 * fix(rustup-init/sh): don't emit "unknown macOS major version" for macOS v11+ * refactor(rustup-init/sh): extract `$_os_major` * refactor(rustup-init/sh): extract `$_os_version` * ci(linux): move `bindgen-cli` installation into `run.bash` * ci(stable): enable `loongarch64-unknown-linux-musl` builds * ci(linux): disable `reqwest-rustls-tls` for unsupported platforms * ci(linux): configure `gcc-multilib` and `libclang` for some *nix builds * chore(deps): bump `aws-lc-rs` and `aws-lc-sys` * download: clean up TLS feature guards * download: simplify feature guards * download: attach download functions to Backend type * download: remove intermediate reqwest-backend feature * Implement more complete backend selection * Simplify logic for download backend notification * docs(dev-guide/tracing): make "Adding instrumentation" a level-2 title * ci(windows): don't install `awscli` via `choco` * test(mock/topical-doc-data): add test cases with both a flag and a topic * refactor(test/mock): use tuples for `topical_doc_data::TEST_CASES` * feat(cli/rustup-mode): allow `rustup doc` with both a flag and a topic * refactor(toolchain): allow passing a fragment in `Toolchain::doc_path()` * refactor(toolchain): allow absolute paths in `Toolchain::doc_path()` * refactor(toolchain): simplify `Toolchain::doc_path()` * refactor(cli/rustup-mode): rename `doc_url` to `doc_path` * refactor(cli/rustup-mode): make `DocPage::path()` return `Option<&Path>` * refactor(cli/rustup-mode): move `DocPage::name()` to a separate `impl` block * refactor(cli/topical-doc): clean up some funtions * refactor(cli/rustup-mode): use early return in `doc()` * Update semver-compatible dependencies * fix: make sure no overflow on small screens * feat: make the box white * feat: use the color form the rust website for tags, hr and copy button * Add the main element and header to setup new layout * chore: remove the old pitch first * Apply clippy suggestions * Append to 1.28.0 changelog * Bump version, commit and date in rustup-init.sh * Clean up trailing whitespace in rustup-init.sh * Add changelog for 1.28.0 * Bump version to 1.28.0 * chore(deps): update remove-dir-all to 1.0 * Add aliases for remove/uninstall/unset commands * feat: add nushell support * Upgrade to opentelemetry 0.27 * fix: add missing close body tag * Upgrade thiserror to 2 * Upgrade to rustls-platform-verifier 0.4 * fix(cli/rustup-mode): remove `.num_args()` when `.value_delimiter(',')` is present * refactor(cli/rustup-mode): remove deprecated `.use_value_delimiter()` * chore(config): migrate config .github/renovate.json * docs: update channel toolchain syntax * feat(cli/rustup-mode): support more books in `rustup doc` * style(cli/rustup-mode): reorder items in `docs_data![]` * fix: add powerpc64 and s390x to known target_arch values for tests * style(utils): put the `mod` declarations below the imports * style: regroup some imports * refactor(utils): hoist `utils::utils` into `utils` * feat(rustup-init): detect and warn about existing `settings.toml` * fix: fix typo in `check_existence_of_rustc_or_cargo_in_path()` * style: allow using `dbg!()` across `rustup::test` * refactor(diskio): replace `eprintln!()` with `debug!()` * style: enable `clippy::(dbg_macro|todo)` across the workspace * style: enable `clippy::print_std(err|out)` when applicable * style: introduce workspace-wide lint tables * build: use `workspace.package` properties in `Cargo.toml` * fix(config): improve error when overridden active custom toolchain isn't installed * fix(config): print special error for invalid toolchain name in override file * Update semver-compatible dependencies, except openssl-src * style(rustup-init/sh): ignore `shellcheck` SC2086 false positives * fix(rustup-init/sh): fix incorrect TLS warning with curl v8.10 * tests: rust-toolchain + profile in settings * Remove unnecessary methods * replace `winreg` dependency * Update remove_dir_all * refactor(cli/common)!: deny installing a host-incompatible toolchain w/o `--force-non-host` * refactor(cli/common)!: take in `toolchain: String` in `warn_if_host_is_incompatible()` * feat(cli/rustup-mode): add `--force-non-host` to `rustup default` * refactor(config)!: pass the `force_non_host` flag to `Cfg::ensure_installed()` * refactor(cli/rustup-mode): rename `forced` to `force_non_host` * docs(README): Point out where to find nightly/master docs. * Note that selecting VS lang packs is optional * Make symlink_or_hardlink_file remove dest * Try symlinking proxies first * Apply clippy suggestions from 1.81 * feat(cli/rustup-mode)!: set log level to `INFO`/`DEBUG` on `--quiet`/`--verbose` if `RUSTUP_LOG` is unset * refactor(cli/setup-mode): extract `update_console_logger()` * fix(cli/setup-mode): simplify description for `--quiet` * feat(cli/setup-mode)!: set log level to `DEBUG` on `--verbose` if `RUSTUP_LOG` is unset * refactor(common)!: remove `verbose` flag in several places * refactor(config): simplify `find_or_install_active_toolchain()` * refactor(config)!: return `LocalToolchainName` from `find_or_install_active_toolchain()` * refactor(config): simplify `resolve_toolchain()` * refactor(config): simplify `toolchain_from_partial()` * chore(triage): allow transferring issues to other org repos * Allow `rustup doc` to search for unions * docs(user-guide): add a link to the latest "Previous components" section * test(cli_v2): introduce `update_removed_component_toolchain()` * feat(dist): add notes for `stable` and `beta` in `components_missing_msg()` * refactor(dist): inline some const strings in `components_missing_msg()` * refactor(dist): extract "nightly tips" out of the match block in `components_missing_msg()` * fix: fix typo in several places * Upgrade pulldown-cmark to 0.12 * fix(manifest): consider possible renames in `Component::try_new()` * ci(macos): install `awscli` from `brew` * refactor(config)!: make `toolchain_from_partial()` sync * feat(config)!: remove implicit installation from `toolchain_from_partial()` * refactor(config)!: make `resolve_toolchain()` sync * feat(config)!: remove implicit installation from `resolve_toolchain()` * test(cli-rustup): remove `heal_damaged_toolchain()` * refactor(config): extract `local_toolchain()` from `resolve_local_toolchain()` * refactor(config): extract `toolchain` variable from `resolve_local_toolchain()` * refactor(config)!: make `resolve_local_toolchain()` sync * feat(config)!: remove implicit installation from `resolve_local_toolchain()` * refactor(config)!: rename `local_toolchain()` to `resolve_local_toolchain()` * feat(rustup-mode): install the active toolchain by default on `rustup toolchain install` * fix(rustup-mode): adjust descriptions for `rustup toolchain uninstall` * feat(rustup-mode)!: add `ensure_active_toolchain` flag to `update()` * feat(config)!: add `verbose` flag to `find_or_install_active_toolchain()` * style(config): replace `dist::Profile` with `Profile` * style(config): replace `dist::TargetTriple` with `TargetTriple` * fix(config): call `warn_if_host_is_incompatible()` in `ensure_installed()` * refactor(common): use early return in `warn_if_host_is_incompatible()` * refactor(rustup-mode): extract `warn_if_host_is_incompatible()` * style(common): merge imports * refactor(distributable)!: avoid unnecessary clones * refactor(distributable)!: replace `install_if_not_installed()` with `ensure_installed()` * feat(config)!: add `verbose` flag to `ensure_installed()` * feat(config)!: return `UpdateStatus` from `ensure_installed()` * feat(config)!: use `Cfg::get_profile()` for unspecified profile in `ensure_installed()` * chore(config): add `#[tracing::instrument]` to `ensure_installed()` * ci(freebsd): fix build failure related to `aws-lc` * ci(windows): don't install OpenSSL via `choco` * ci(run): remove redundant `if` predicate * ci(run): use the detected number of test threads * feat(download/rustls): use `aws-lc` instead of `ring` * style(taplo): enable `reorder_keys` for `*dependencies` in `Cargo.toml` * Upgrade windows-sys to 0.59 * fix: fix unreachable code lints on Android * docs(dev-guide): remove descriptions of `rustup_macros` * docs(dev-guide): update description of `rustup::process` * Remove `once_cell` dependency * docs(dev-guide): add guideline for atomic commits to the developer guide * fix: fix `clippy` lints * docs(user-guide): use `brew install rustup` instead of `rustup-init` * Bump fs_at to 0.2.1 * chore(deps/renovate): disable `automerge` * Upgrade to opentelemetry 0.24 * build(windows): don't link against `powrprof` * build(windows): fix typo in `build.rs` * fix(utils): make `ExitCode` `#[must_use]` * refactor(rustup-mode): introduce `ExitCode::bitand*()` * fix(rustup-mode): return `ExitCode(1)` when `update()` fails * refactor(rustup-mode)!: remove redundant `ExitCode` in `self_update()`'s callback * test(cli-misc): simplify `version_mentions_rustc_version_confusion()` * fix(rustup-mode): refine output for `rustup --version` * fix(rustup-mode)!: don't install toolchain on `rustup --version` * chore(deps/renovate): update `automerge` schedule for `lockFileMaintenance` * ci(check): add `taplo fmt` test for TOMLs * style: reformat all TOMLs with `taplo` * ci(gen-workflows): remove `--quiet` from `git diff` * refactor: use `#[cfg()]` instead of `cfg!()` when possible * refactor(self-update): remove outdated `do_pre_install_sanity_checks` * Add help message for missing toolchain * Rename OSProcess to OsProcess * Rename currentprocess to process * Forward to Process::var_os() directly * Fix home_dir() and current_dir() regression * feat(log): set level of `#[tracing::instrument(err)]` to `TRACE` * feat(log): unhide `tracing::instrument` from behind `feature = "otel"` * ci(windows): increase stack size to 16MiB * Upload Windows artifacts into correct subdirectory * Fix uploading of Windows build artifacts * Prepare deployment on master branch * Grant GitHub Actions workflows access to OIDC token * chore(deps): update aws-actions/configure-aws-credentials action to v4 * Authenticate CI uploads with OIDC * Upload release artifacts to new S3 bucket * chore(deps/renovate): set `prCreation` to `immediate` * feat(dist): refine suggestions regarding manifest checksum mismatches * refactor(config): extract `dist_root_server()` * refactor(dist): use `let-else` in `dl_v2_manifest()` * refactor(dist/notifications)!: inline usages of `Notification::ManifestChecksumFailedHack` * refactor(install): avoid extra clone in `InstallMethod::install` * Reorder operations in order to simplify * Deduplicate handling of environnment variables * Move if_not_empty() to calling module * feat(cli): warn when removing the default/active toolchain * feat(cli): improve warning when removing the last/host target for a toolchain * docs(ci): simplify the target policy in the README * Add loongarch64-unknown-linux-musl support * fix(download): fix build error with `--no-default-features --features=curl- backend` * feat(rustup-init): set log level to `WARN` on `-q` if `RUSTUP_LOG` is unset * implements quiet flag in `rustup-init.sh` * test(manifestation): introduce and migrate tests to `TestContext` * chore(manifestation): organize imports * add regression tests for smart guess * apply smart guess to `rustup update/uninstall self` * Disable automatic self updates in CI environments * feat(download/rustls): use `rustls-platform-verifier` * ci(windows): run `cargo all-features` * fix(self-update/windows): address some `unused_imports` warnings * fix(rustup-mode): improve `clap` error format * Add period in warning while checking existing rust installations * Move Windows-only test code into windows module * Asyncify CLI tests * Use guard type to replace with_saved_path() * Refactor test registry state to be more type safe * Inline single-use with_saved_global_state() function * Privatize with_saved_global_state() * Move change_dir() into CliTestContext * Move with_update_server() into CliTestContext * Remove Config::with_scenario() * Port cli_v2 to CliTestContext * Port cli_v1 to CliTestContext * Port cli_self_upd to CliTestContext * Port cli_rustup to CliTestContext * Port cli_paths to CliTestContext * Port cli_misc to CliTestContext * Port cli_inst_interactive to CliTestContext * Port cli_exact to CliTestContext * Use CliTestContext directly in self_update_setup() * Start CliTestContext type wrapper * docs(dev-guide/tracing): mention `RUSTUP_LOG` and console-based tracing * docs(dev-guide/linting): improve wording * test(dist): add simple tests for `PartialVersion` * chore(dist): add some doc comments * fix(dist): throw an error when a `PartialVersion` string doesn't start with an ASCII digit * ci(all-features): add `-D warnings` to `cargo check-all-features` * fix(currentprocess/filesource): address some `unused_imports` warnings * fix(currentprocess): address some `unused_imports` warnings * fix(regex): replace `\d` to `[0-9]` to avoid matching non-ASCII digits * refactor(toolchain/names): replace `toolchain_sort` with `ToolchainName`'s `Ord` instance * refactor(dist)!: make `ToolchainDesc.channel` more strongly typed * Remove unnecessary lint suppressions * Use local suppression for clippy::too_many_arguments * Rename desc fields to toolchain * Remove intermediate state from error handling * Remove indirection in update error handling * Inline wrapper function * Reduce rightward drift * Propagate use of DistOptions * Avoid unnecessary unwrapping * Extract struct from InstallMethods::Dist variant * refactor(log): replace the `TELEMETRY_DEFAULT_TARCER` singleton with a function * test(clitools): revive `run_inprocess()` * fix(dist/arm): don't assume `armv7` if `/proc/cpuinfo` is unavailable * fix(dist): add fallbacks to `/proc/self/exe` in `rustup-init.sh` * Rename default-tls to native-tls * Inline small errors module * Inline addition/removal to programs * Move windows-only self_update code into windows module * Reorganize platform-dependent imports in self_update * refactor(log): replace `[Ww]arning:` log line prefix with `warn:` * refactor(log): rename `NotificationLevel::Debug` to `Trace` and `Verbose` to `Debug` * Remove unused code * Hoist Toolchain up into top-level toolchain module * Remove unused derived sorting implementations * Privatize internal organization of toolchain module * Inline argument * Inline trivial wrapper * Move toolchain resolution into Cfg method * Check settings version on Cfg construction * Move proxy toolchain resolution logic into Cfg method * Move rustc_version() function into Cfg * Expose higher-level interface in Toolchain * Move DistributableToolchain::installed_paths() into Cfg * No need to store cfg in DistributableToolchain * Reduce indirection in Cfg::from_partial() * Move Toolchain::from_partial() to Cfg * Take owned LocalToolchainName in Toolchain::from_local() * Simplify Toolchain::from_local() * refactor(dist): hoist `dist::dist` into `dist` * refactor(dist): privatize imports from `dist::dist` * Fix the `TODO` in `src\toolchain\toolchain.rs` * Use tracing macros directly * Inline single-caller maybe_trace_rustup() * Remove rustup test wrapper macros * Use tokio::main attribute * Attach Process-dependent utils to Process * Remove with_runtime() * fix(config): fix typo in `ActiveReason` * fix(log): use `RUSTUP_LOG` for internal `tracing` instead of `RUST_LOG` * refactor(currentprocess): make use of `Arc::default()` * refactor(currentprocess): rename `TestProcess.guard` to `_guard` * Remove currentprocess::with() * Privatize most TestProcess fields * Remove unused TestProcess::id * Pass Process around explicitly * Let argument parser handle SelfUpdateMode conversion * Let argument parser handle Profile conversion * Use simpler form for string concatenation * Reduce rightward drift by duplicating some Ok-wrapping * Rename _install_selection() to IInstallOpts::install() * Inline async closure * Move error mapping out of validation function * Rename do_pre_install_options_sanity_checks() to InstallOpts::validate() * Rename customize_install() to InstallOpts::customize() * Pass InstallOpts around directly * refactor(terminalsource): use `.eq_ignore_ascii_case()` in `ColorableTerminal::new` * chore(notify): sort logging macros and `NotificationLevel` on verbosity * chore(env): retire `RUSTUP_DEBUG` in favor of `RUST_LOG` * feat(log): make `console_logger()` accept `RUSTUP_TERM_COLOR` and `NO_COLOR` * refactor(log): reimplement `log` using `tracing` * refactor(test): clean up `before_test_async()` * chore(deps): make `tracing-subscriber` a hard requirement * refactor(test): setup `tracing` subscriber in `before_test_async()` * test(clitools): disable `run_inprocess()` * refactor(test): execute all `#[rustup_macros::unit_test]`s within a `tokio` context * refactor(log): extract `telemetry()` * Remove noop functions in favor of conditional compilation * Avoid trivial wrapper functions * Store process name in error variant directly * Inline trivial wrapper function * Fix misleading "uninstalled toolchain" notification * refactor(ci/run): use more `target_cargo()` in `run.bash` * Remove trivial new() implementation * Use serde to encode/decode mock manifests * Use serde to encode/decode rustup manifests * Use serde to encode/decode config * Represent config version as an enum * Use serde to encode/decode manifests * Represent manifest version as enum * Use serde to encode/decode settings * Add tests for settings encoding * Derive Default for Settings * Represent metadata version as an enum * Use Default impl for Settings::profile default * Derive Default for Profile * Discard unnecessary layer of Arc * Externalize wrapping of DownloadTracker * Inline NotifyOnConsole * Internalize interior mutability for Notifier * Decouple Cfg from Notifier initialization * fix(dist/triple): ensure `dist::triple::known` is up to date with `platforms` * refactor(toolchain): reuse `dist::triple::known` in `toolchain::names` * refactor(dist/triple): move known triples to `dist::triple::known` * refactor(build): use `platforms` to verify `RUSTUP_OVERRIDE_BUILD_TRIPLE` * refactor(build): simplify the code obtaining the current triple * feat(cli): add `--quiet` to `rustup (target|component) list` * feat(cli): add `--quiet` to `rustup toolchain list` * Inline trivial single-use function utils::to_absolute() * Inline trivial single-use function Cfg::which_binary() * Inline short single-use function direct_proxy() * Rename new_toolchain_with_reason() to Toolchain::with_reason() * Move Cfg::maybe_do_cargo_fallback() to Toolchain * Move Cfg::create_command_for_toolchain() to Toolchain::command() * Extract common usage of Cfg::create_command_for_toolchain() * Inline trivial single-use function Cfg::create_command_for_dir() * Inline simple function Cfg::create_command_for_toolchain() * Move toolchain construction out of Cfg::create_command_for_toolchain() * Inline single-use function * Improve error message for failing .rustup creation * Inline trivial single-use function * Inline utils::current_dir() * Take explicit current_dir argument in to_absolute() * Pass current_dir down from main() * Update rustup.rs website to offer Rustup on Windows on Arm * Use Cfg::current_dir in override_remove() * Use Cfg::current_dir in override_add() * Use Cfg::current_dir in find_or_install_active_toolchain() * Use Cfg::current_dir for create_command_for_dir() * Use Cfg::current_dir for find_or_install_active_toolchain() * Store current_dir in Cfg for use in find_active_toolchain() * Enable building Rustup win-aarch64 on PR * Add aarch64-apple-darwin and aarch64-pc-windows-msvc to cloudfront- invalidation.txt * Update Other installation methods page to include aarch64-pc-windows-msvc * Remove unnecessary trait abstraction * Simplify process access to current_dir * Simplify process access to environment variables * Remove unnecessary trait bound for home::Env * Simplify process access to pid * Simplify process access to stdin * Simplify process access to stderr * Simplify process access to stdout * Simplify process access to argument iterator * fix(download): work around `hyper` hang issue by adjusting `reqwest` config * test(download): fix clippy warnings regarding `Mutex` in `async` * test(dist): add regression tests for parsing beta versions with tags * test(dist): introduce scenario `BetaTag` with mock test data * feat(dist): add support for parsing beta versions with tags in the toolchain * refactor(utils): move `run_future()` under `manifestation` * feat(config): make `create_command_for_toolchain()` async * refactor(config): make `update_all_channels()` async * refactor(self_update): make `maybe_install_rust()` async * refactor(config): make `ensure_installed` async * fix expected path-separators on windows * add a regression test * consistently add context with file path when parsing fails * ci(windows/gnu): install `mingw` via `bwoodsend/setup-winlibs-action` * ci(windows): enable CI on `x86_64-pc-windows-gnu` * Make manifestation test update_from_dist async * Make update async * Make default_ async * Make check_updates async * Make target_add async * Make target_remove async * Make component_add async * Make component_remove async * Make update_all_channels async * Make toolchain_link async * Make override_add async * Make DistributableToolchain::remove_component async * Make DistributableToolchain::add_component async * Make DistributableTool::install_if_not_installed async * Make DistributableToolChain::install async * Make toolchain.update async * Make update_extra async * Make show_dist_version async * Make InstallMethod::install async * Make InstallMethod::run async * Make update_from_dist async * Make update_from_dist_ async * Make try_update_from_dist_ async * Make update_v1 async * Make dist::dl_*_manifest async * Make common::self_update async * Make manifestation::update async * Make download retries async * Make DownloadCfg::download_and_check async * Make DownloadCfg::download_hash async * Make self_update::update async * Make check_rustup_update async * Make prepare_update async * Make get_available_rustup_version async * Make setup_mode::main async * Make self_update::install async * Make try_install_msvc async * Make download_file async * Make DownloadCfg::download async * Make download_file_with_resume async * Make download_file_ async * Make download_to_path_with_backend async * Make download_with_backend async * Make rustup_mode::main async * Convert run_rustup_inner to async * Make run_rustup async * Remove maybe_trace_rustup runtime setup * Make maybe_trace_rustup async * Convert main to using a tokio runtime always * Ring 0.17.x support Windows on ARM * ci(macos): use `macos-latest` instead of `macos-14` * fix(deps): update rust crate itertools to 0.13 * fix(deps): update rust crate pulldown-cmark to 0.11 * Avoid unnecessary allocations * Attempt to reduce duplication by adding a little abstraction * Move explicit_desc_or_dir_toolchain() to Toolchain::from_partial() * Propagate ExitStatus instead of custom ExitCode * Use precise internal imports * Use idiomatic way to proxy str data * Inline RustupSubcmd::dispatch() * refactor(filesource): replace repetitive `#[cfg()]` usages with a new `mod` * Fix ETA display after regression * Stop showing ETA after download is complete * refactor(cli): hoist the `handle_epipe()` call out of the `match` * refactor(cli): rewrite `rustup` itself with `clap-derive` * refactor(cli): rewrite `rustup (self|set)` with `clap-derive` * refactor(cli): rewrite `rustup (man|completions)` with `clap-derive` * refactor(cli): rewrite `rustup doc` with `clap-derive` * refactor(cli): rewrite `rustup (run|which|dump-testament)` with `clap- derive` * refactor(cli): rewrite `rustup override` with `clap-derive` * refactor(cli): rewrite `rustup component` with `clap-derive` * refactor(cli): rewrite `rustup target` with `clap-derive` * refactor(cli): rewrite `rustup (check|default)` with `clap-derive` * refactor(cli): rewrite `rustup (toolchain|update|(un)?install)` with `clap- derive` * refactor(cli): remove `deprecated()` * refactor(cli): rewrite `rustup show` with `clap_derive` * fix(rustup-init): fix typo in `rustup-init[.sh]` args * feat(download): reflect the download/TLS backends in the user agent * Make find_override_from_dir_walk return OverrideCfg * Make settings file allow multiple borrows * Fix doc error with `rust-toolchain.toml` custom TC * Make `rustup default` not error if no default * Update format of `toolchain list` * Update format of `show` and `show active-toolchain` * Redesign OverrideCfg to be more type-driven * Pull match statement out in OverrideCfg::from_file() * Change find_override to find_active_toolchain * Pull out `new_toolchain_with_reason()` * Pull out `ensure_installed()` * refactor(cli): reorder `if` statement in `cli::setup_mode::main()` * refactor(cli): rewrite `rustup-init` with `clap_derive` * Avoid code duplication for printing target/component items * Deduplicate code to get components from distributable * Merge list_{,installed_}targets * Merge list_{,installed_}components functions * fix(filesource): make some constructs only available via the `test` feature * fix(ci/freebsd): install ca certs to prevent `invalid peer certificate: UnknownIssuer` * feat(download-backend)!: make `reqwest/rustls` the new default * feat(download-backend)!: refine selection logic * Update MSVC requirements to VS 2017 to match Rust repo * refactor(download): use `DownloadCallBack` in `download_with_backend()` * ci: don't build for `i686-linux-android` due to OpenSSL v3 atomic issues * ci(android): update NDK version * fix(deps): update rust crate openssl-src to v300 * ci(linux-gnu): install `perl-IPC-Cmd` to make OpenSSL v3 happy * chore(deps): update ubuntu docker tag to v24 * docs(dev-guide): remove "pushing to master" in the release process * Replace remaining winapi usage with windows-sys Update to version 1.27.1~0: * chore(dist): update commit shasum in `rustup-init.sh`, take 2 * fix(ci/linux): don't use `pip3` to install `awscli` * fix(ci/macos): don't use `pip3` to install `awscli` * chore(dist): update commit shasum in `rustup-init.sh` * docs: update CHANGELOG for v1.27.1 * feat(dist): improve `changelog_helper` script * dist: bump `rustup` version to `1.27.1` * chore: fix some typos in comments * Remove TryFrom for TargetTriple * Add tests for add/remove components by name with target triple * Replace Component::new_with_target by Component::try_new * refactor(self-update)!: remove confusing `get_path()` impl on Unix * test(self-update): ensure the resolution of #3739 * feat(self-update): add `with_saved_reg_value()` * refactor(self-update): extract `(get|restore)_reg_value()` * refactor(self-update): extract `with_saved_global_state()` * refactor(self-update): use `std::io` * fix(self-update): replace some `#[cfg(not(unix))]` usages with `#[cfg(windows)]` * feat(self-update): improve error messages on Windows * fix(self-update): run `do_update_programs_display_version()` on `run_update()` * refactor(self-update): extract `get_and_parse_new_rustup_version()` * refactor(self-update): extract `do_update_programs_display_version()` * ci: don't test for FreeBSD on PRs * docs(user-guide): update `environment-variables` * refactor(self-update): eliminate needless clone * feat(self-update): log `RUSTUP_DIST_*` if it's set * feat(self-update): log `RUSTUP_UPDATE_ROOT` if it's set * refactor(self-update): rename `UPDATE_ROOT` to `DEFAULT_UPDATE_ROOT` * refactor(self-update): extract `update_root()` * once_cell only used with reqwest in download crate, so gate it * tracing unsed only from otel feature, so move it to optional * Add loongarch64-unknown-linux-gnu to installation docs * Add loongarch64-unknown-linux-gnu to cloudfront invalidations * Use pattern matching to make Debug impl for Cfg more robust * Use std IsTerminal interface * Rename temp::Cfg to Context * temp: keep definitions and impls together * Remove derivative dependency in favor of manual implementation * docs(dev-guide): move all mentions of `cargo clippy` to `linting.md` * docs(dev-guide): mention that we need to keep mdBook links stable * refactor(utils)!: rename `delete_dir_contents()` to `delete_dir_contents_following_links()` * fix(utils): resolve input path in `delete_dir_contents()` if it's a link * test(cli): ensure the resolution of #3344 * Revert "fix(utils): unlink input path in `delete_dir_contents()` if it's a link" * Revert "refactor(utils)!: rename `delete_dir_contents()` to `delete_dir_contents_or_unlink()`" * Revert "test(cli): ensure the resolution of #3344" * refactor(utils)!: rename `delete_dir_contents()` to `delete_dir_contents_or_unlink()` * fix(utils): unlink input path in `delete_dir_contents()` if it's a link * test(cli): ensure the resolution of #3737 * refactor(util)!: rename `open_dir()` to `open_dir_following_links()` * fix(utils): don't use `O_NOFOLLOW` in `open_dir()` * chore: fix typo in `CHANGELOG` * chore(meta): update `bug_report` issue template * Add hr to Windows instructions * fix(doc): don't show the opening message when --path is used * chore: remove repetitive words * fix(deps): update rust crate opener to 0.7.0 * fix(config): remove unnecessary debug print * fix(ci): fix file paths in CI-generated `*.sha256` files on *nix * fix(ci): correct error message after bumping reqwest * fix(deps): update rust crate reqwest to 0.12 * doc(dev-guide): Fix test Lint and add explanation * Fix "component add" error message * ci: use `stable` Rust for all clippy lints * style: apply clippy suggestions from Rust 1.78.0 * fix(ci/windows): disable `cargo clippy` on `*-windows-gnu` * fix(shell): create parent dir before appending to rcfiles * fix(fish): fix definition of `Fish::update_rcs` * docs(dev-guide): update `release-process.md` to match the new workflow based on GitHub Merge Queue * ci(macos): add `MACOSX_DEPLOYMENT_TARGET` and friends * Replaced `.` with `source` in fish shell's `source_string` * Deny clippy warnings in CI * Rely on implicit conversion to OperationResult * Extract closure from match scrutinee * fix(cli): fix incorrect color state after `ColorableTerminal::reset` * docs: Add note about stability of llvm-tools. * Change default for RUSTUP_WINDOWS_PATH_ADD_BIN * ci: remove direct `renovate/*` tests * Fix dead_code and unused_imports warnings Update to version 1.27.0~0: * docs: update `CHANGELOG` for v1.27.0 * hack(deps): pin `openssl-sys` to 0.9.92 * fix #3663. Feedback in terminal when opening browser for docs * Fix copy icon position in Safari * Upgrade to opentelemetry 0.22 * fix ambiguous prompt after setting up custom installation * docs: rephrase and split sentence about Visual Studio license * Add comment on why we prefer symlinks to junctions * Windows: Try using symlinks if they're allowed * chore(ci): unify the matrix format to (mode, target) * ci: update runners for macOS-related workflows * docs: mention `apt` in installation methods * docs: fix missing links in `CHANGELOG.md` * chore(deps): update rust crate trycmd to 0.15.0 * fix(deps): downgrade `openssl-sys` to 0.9.92 * ci: remove the now-tier3 `mips*-unknown-linux-gnu*` targets from the build * Update mdbook and fix some source issues. * Rename `.cargo/config` to `.cargo/config.toml` * chore: update `CHANGELOG.md` * dist: bump `rustup-init.sh` version to `1.27.0` * dist: bump `rustup` version to `1.27.0` * feat: introduce `changelog_helper` script * Upgrade to pulldown-cmark 0.10 * Fix some typos * fix(deps): update rust crate libc to 0.2.153 * Download rust CI Docker images from a registry * Component is now named 'llvm-tools' * chore: add docstring to `is_32bit_userspace()` * chore: disable some unix-only helper functions on Windows * chore(deps): update actions/cache action to v4 * refactor(cli): simplify case splitting on `clap::error::ErrorKind` * refactor(names): replace `maybe_official_toolchainame_parser` with `impl FromStr` * refactor: simplify `is_proxyable_tools` * refactor(distributable): import `ComponentStatus` * refactor(cli): avoid nested combinators in `has_at_most_one_target` * feat(cli): warn when removing the last/host target for a toolchain * refactor(toolchain): extract `DistributableToolchain::components()` * www: detect RISC-V 64 platform * fix(deps): update rust crate strsim to 0.11 * chore(deps): update `renovate.json` to remove version bumps covered by lockfile maintenance PRs, take 3 * feat(ci): configure `merge_queue` to be a PR-like event * feat(ci): enable the `merge_group` trigger * fix(ci): use `github.event_name == 'schedule'` instead of `github.event.schedule` * chore(deps): update `renovate.json` to remove version bumps covered by lockfile maintenance PRs, take 2 * fix(deps): update rust crate clap to v4.4.13 * fix(deps): update rust crate syn to v2.0.48 * chore(deps): update rust crate opentelemetry_sdk to v0.21.2 * fix(ci): use `github.event_name == 'push'` instead of `github.event.push` * feat(ci): add CI workflow generation checks * refactor(ci): disassemble and reorganize `ci/cirrus-templates` * feat(ci): add `conclusion` job * refactor(ci): move `freebsd-builds` to GitHub Actions * refactor(ci): merge all current GitHub Actions workflows into `ci.yaml` * chore(ci): clean up current CI files * chore(deps): update `renovate.json` to remove version bumps covered by lockfile maintenance PRs * fix(deps): update rust crate syn to v2.0.47 * fix(deps): update rust crate proc-macro2 to v1.0.75 * fix(deps): update rust crate clap_complete to v4.4.6 * fix(deps): update rust crate serde to v1.0.194 * fix(deps): update rust crate semver to v1.0.21 * chore(deps): update rust crate thiserror to v1.0.56 * chore(deps): update rust crate anyhow to v1.0.79 * fix(deps): update rust crate syn to v2.0.45 * fix(deps): update rust crate proc-macro2 to v1.0.73 * fix(deps): update rust crate syn to v2.0.44 * fix(deps): update rust crate quote to v1.0.34 * fix(deps): update rust crate proc-macro2 to v1.0.72 * chore(deps): update rust crate anyhow to v1.0.78 * chore(deps): update rust crate thiserror to v1.0.53 * fix(deps): update rust crate clap to v4.4.12 * chore(deps): update rust crate tempfile to v3.9.0 * fix(deps): update rust crate clap_complete to v4.4.5 * chore(deps): update rust crate anyhow to v1.0.77 * chore(deps): update rust crate thiserror to v1.0.52 * fix(deps): update rust crate syn to v2.0.43 * fix(deps): update rust crate openssl to v0.10.62 * fix(deps): update rust crate proc-macro2 to v1.0.71 * fix(deps): update rust crate syn to v2.0.42 * chore(deps): update rust crate anyhow to v1.0.76 * chore(deps): update rust crate hyper-util to v0.1.2 * chore(deps): update rust crate tokio to v1.35.1 * fix(deps): update rust crate reqwest to v0.11.23 * chore(deps): update rust crate hyper to v1.1.0 * docs: move "rls" and "rust-analysis" to separate section "previous..." (#3591) * chore(deps): update actions/upload-artifact action to v4 * Fix rustup-init failure to read ZDOTDIR from zsh when SHELL is not zsh (#3584) * CI: Enable rustls on loongarch64 * CI: Revert "Disable openssl for loongarch64-unknown-linux-gnu" * fix(deps): update rust crate openssl-src to v300.2.1+3.2.0 * fix(deps): update rust crate syn to v2.0.41 * fix(deps): update rust crate syn to v2.0.40 * fix(deps): update rust crate libc to v0.2.151 * chore(deps): update rust crate once_cell to v1.19.0 * fix(deps): update rust crate clap to v4.4.11 * fix(deps): update rust crate openssl to v0.10.61 * Fix test permanently adding to PATH * chore(deps): revert `Cargo.toml` bump in #3540 * chore(deps): revert `Cargo.toml` bump in #3532 * chore(renovate): prevent unnecessary `Cargo.toml` bumps * Lock file maintenance * Fix panic in `component list --toolchain stable` * Upgrade hyper to 1.0 (#3543) * Clarify several docs and help messages * Remove rel paths from rust-toolchain.toml docs * CI: Disable openssl for loongarch64-unknown-linux-gnu * Update Rust crate url to 2.5 * Update Rust crate winreg to 0.52 * Update Rust crate windows-sys to 0.52.0 * Update Rust crate termcolor to 1.4 * Streamline dependencies in `Cargo.toml` * Update opentelemetry * [doc] windows.md: fix link * Inline channel pattern list * Remove unused import * Explicitly import symbols * Remove unused dependencies from macros crate * Replace usage of lazy_static with once_cell * Use more conventional field order in package table * Remove authors from Cargo manifest (per RFC 3052) * Use uniform dependency specification style * Inline `semver::Version` in `toolchain_sort` * Add docs specifying `toolchain_sort`'s expected behavior * Change key used in `toolchain_sort` * Inline `special_version` in `toolchain_sort` * Inline `toolchain_sort_key` in `toolchain_sort` * Replace `sort_by` with `sort_by_key` in `toolchain_sort` * Refine `test_toolchain_sort` * Suggest installing MSYS2 for `windows-gnu` * Fix the test toolchain_broken_symlink on Windows * Move `TOOLSTATE_MSG` to `dist` to serve toolchain-wide operations * Add test to ensure resolution of #3418 * Add `Panics` sections to docstrings * Refactor `components_*_msg` * Delete suggestions of removing the relevant component from `component_unavailable_msg` * Clean up some `manifestation` logic * Warn when running under Rosetta emulation * Typo fixed in tips-and-tricks.md file * Adjust suggestions about sourcing `env` files * Restrict zsh `shwordsplit` to `downloader()` * Update Rust crate zstd to 0.13 * Apply `clippy` suggestions * Extract `post_install_msg_unix_source_env!()` * Add suggestions to mention sourcing `env.fish` * Fix zsh word splitting for curl "\--retry 3" * Add ksh compatibility for latest illumos and others * Remove redundant message if an error occurs during package extraction * Update Rust crate regex to 1.10.0 * Write a custom env script for fish * Fix fish config dir paths * Update all rc fish scripts * Try to add support for fish shell * Clarify the origin of `rust-$TARGET` CI Docker images * Apply more `clippy` suggestions * Capturing IO error in download_file_with_resume (#3421) * Adjust instructions for manual installation (#3502) * Windows: Load DLLs from system32 * When running a 32-bit rustup on an aarch64 CPU, select a 32-bit toolchain * Do not fallback to "arm" in rustup-init.sh on aarch64 with 32-bit userland * Update Rust crate toml to 0.8 * Mention `brew install rustup-init` in the user guide * Adjust section titles in the user guide * Update actions/checkout action to v4 * Avoid warning for unused variant * fix invalid link for 1.25.2 * 1.26.0 should not be unreleased in the changelog * Refactor test case `install_uninstall_affect_path` * Update Rust crate winreg to 0.51 * Apply clippy suggestions from Rust 1.74 (#3497) * Fix rustup_only_options_stdout * Bring additional help section style in line with clap 4 * Upgrade to clap 4 * Avoid deprecated clap API * Isolate trycmd tests from environment * Update Rust crate tracing-opentelemetry to 0.21.0 * buf writes to components * Update Rust crate tempfile to 3.8 * Return the right lifetime from DistributableToolchain::install * Fix handling of async tests * Improve CI debugability * Refactor: Use download_cfg.notify_handler in update() * Authenticate when installing protoc * Avoid installing protoc for most CI workflows * Refine suggestions of sourcing `$HOME/.cargo/env` * Avoid `sysctl: unknown oid` stderr output and/or non-zero exit code * Configure automerge in Renovate * Fix renovate.json * Make `RUSTUP_TERM_COLOR`'s value case insensitive * Add unit tests for `RUSTUP_TERM_COLOR` * Support `RUSTUP_TERM_COLOR` as an override environment variable * macOS `uname -m` can lie due to Rosetta shenanigans * Migrate CONTRIBUTING.md to an mdbook * Build docs during CI * Move the user guide from doc to doc/user-guide * Update Rust crate tempfile to 3.7 * Use available_parallelism replace the `num_cpus`crate * rustup-init.sh: Check for kernel UAPI compatibility on LoongArch * Enable loongarch64-linux-gnu builds on stable * allow `clippy::arc_with_non_send_sync` * Address `#[warn(clippy::useless_vec)]` * Address `#[warn(clippy::needless_borrow)]` * Address `#[warn(clippy::useless_conversion)]` * Address `#[warn(clippy::redundant_pattern_matching)]` * Address `#[warn(clippy::redundant_field_names)]` * Bump proc-macro2 v1.0.51 -> v1.0.63 * Bump the openssl v0.10.52 -> v0.10.55 * Fix typo: prerequistes -> prerequisites * update installation methods to use TLS v1.2 * Disable the "oldtime" feature of chrono * Update Rust crate tempfile to 3.6 * Update Rust crate url to 2.4 * Update Rust crate once_cell to 1.18.0 * Make download_tracker thread safe. * Enable broken color in MSYS2 shells * Add suggest_message helper for errors * replace term with termcolor * Tweak docs * Improve error message for removing uninstalled target * Improve error message for adding unknown target * CI support for loongarch64-unknown-linux-gnu * Fix compile on rust nightly * Group updates to opentelemetry together * Improve CurrentProcess * Update dependencies * TestProcess and friends should be test only * Update Rust crate windows-sys to 0.48.0 * Rework Toolchain model and drop relative file path overrides * Add in opentelemetry tracing as a feature * Remove repeated definite article * Make clippy happy * Update Rust crate toml to 0.7.3 * Suggest right toolchain when running clippy * Fix small typo * Update Rust crate winreg to 0.50 * Update Rust crate tempfile to 3.5 * Compile static Mutex where possible * Upgrade CI image to FreeBSD 13.2 * Update Rust crate opener to 0.6.0 * Update Rust crate enum-map to 2.5.0 * Bumped retry ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2831=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2831=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2831=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2831=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2831=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2831=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * openSUSE Leap 15.4 (aarch64 x86_64) * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * rustup-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * rustup-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * rustup-1.28.2~0-150400.3.13.1 * rustup-debuginfo-1.28.2~0-150400.3.13.1 * rustup-debugsource-1.28.2~0-150400.3.13.1 ## References: * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1203257 * https://bugzilla.suse.com/show_bug.cgi?id=1230032 * https://bugzilla.suse.com/show_bug.cgi?id=1243862 * https://bugzilla.suse.com/show_bug.cgi?id=1249008 * https://bugzilla.suse.com/show_bug.cgi?id=1257902 * https://bugzilla.suse.com/show_bug.cgi?id=1270186 * https://bugzilla.suse.com/show_bug.cgi?id=1270521 * https://bugzilla.suse.com/show_bug.cgi?id=1270619 * https://bugzilla.suse.com/show_bug.cgi?id=1270644 * https://bugzilla.suse.com/show_bug.cgi?id=1270795 * https://bugzilla.suse.com/show_bug.cgi?id=1270870 * https://bugzilla.suse.com/show_bug.cgi?id=1270874 * https://bugzilla.suse.com/show_bug.cgi?id=1270989 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:32:03 -0000 Subject: SUSE-SU-2026:2830-1: important: Security update for warewulf4 Message-ID: <178367232394.944.2556428299909209396@530c474df1e7> # Security update for warewulf4 Announcement ID: SUSE-SU-2026:2830-1 Release Date: 2026-07-09T18:42:10Z Rating: important References: * bsc#1254470 * bsc#1258511 * bsc#1262810 * bsc#1265653 * bsc#1266483 * bsc#1268790 Cross-References: * CVE-2025-69725 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 CVSS scores: * CVE-2025-69725 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:N/SA:N * CVE-2025-69725 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-69725 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 An update that solves four vulnerabilities and has two security fixes can now be installed. ## Description: This update for warewulf4 fixes the following issues: Update to v4.7.0. Security issues fixed: * CVE-2025-69725: incorrect input validation in the `RedirectSlashes` function can lead to an open redirect (bsc#1258511). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` can lead to a denial of service (bsc#1265653). * CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262810). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266483). Other updates and bugfixes: * Add correct flag `--update-overlays` fix (bsc#1268790). * v4.7.0: * New `wwctl` unset command * Refactored server routes (URLs) * New `/files/` route for serving individual files and templates * Server TLS support * Removed support for fetching individual overlays and individual files from overlays * Fixed whitespace handling around template functions * Security fixes, including updated Go and library versions * v4.6.5: * New wwctl overlay info command * Fixed `wwctl` image import `--update` option * Cross-arch support for `wwclient` * Improved IPv6 support * Improved support for bonded interfaces * Renamed `debian.interfaces` overlay to `ifupdown` * New `systemd-networkd` overlay * `warewulf-dracut` fixes, including `provision-to-disk` fixes * Remove `slurm-overlay` package. * Fix `wwctl` image import `--update` option (bsc#1254470). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2830=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2830=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2830=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2830=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-2830=1 ## Package List: * openSUSE Leap 15.5 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * warewulf4-overlay-rke2-4.7.0-150500.6.42.1 * openSUSE Leap 15.5 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * HPC Module 15-SP7 (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * HPC Module 15-SP7 (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * warewulf4-overlay-4.7.0-150500.6.42.1 * warewulf4-4.7.0-150500.6.42.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * warewulf4-dracut-4.7.0-150500.6.42.1 * warewulf4-reference-doc-4.7.0-150500.6.42.1 * warewulf4-man-4.7.0-150500.6.42.1 ## References: * https://www.suse.com/security/cve/CVE-2025-69725.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1254470 * https://bugzilla.suse.com/show_bug.cgi?id=1258511 * https://bugzilla.suse.com/show_bug.cgi?id=1262810 * https://bugzilla.suse.com/show_bug.cgi?id=1265653 * https://bugzilla.suse.com/show_bug.cgi?id=1266483 * https://bugzilla.suse.com/show_bug.cgi?id=1268790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:32:15 -0000 Subject: SUSE-SU-2026:2829-1: important: Security update for libaom Message-ID: <178367233561.944.12347712097189157698@530c474df1e7> # Security update for libaom Announcement ID: SUSE-SU-2026:2829-1 Release Date: 2026-07-09T18:40:25Z Rating: important References: * bsc#1268650 * bsc#1268651 * bsc#1268653 * bsc#1268655 Cross-References: * CVE-2026-56208 * CVE-2026-56209 * CVE-2026-56210 * CVE-2026-56211 CVSS scores: * CVE-2026-56208 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56208 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56208 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-56209 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56209 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56209 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-56210 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56210 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56210 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-56211 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56211 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-56211 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libaom fixes the following issues: * CVE-2026-56208: untrusted encoder configuration inputs can lead to a heap- based buffer overflow and a process crash (bsc#1268650). * CVE-2026-56209: crafted video frames with specific Y-plane pixel values can lead to an arbitrary memory write (bsc#1268651). * CVE-2026-56210: missing bounds check on layer_id inputs can lead to an out- of-bounds heap read (bsc#1268653). * CVE-2026-56211: out-of-range spatial/temporal layer selection can lead to remote code execution (bsc#1268655). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2829=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2829=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2829=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2829=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2829=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2829=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2829=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2829=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2829=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libaom3-64bit-debuginfo-3.7.1-150400.3.12.1 * libaom3-64bit-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (x86_64) * libaom3-32bit-3.7.1-150400.3.12.1 * libaom3-32bit-debuginfo-3.7.1-150400.3.12.1 * openSUSE Leap 15.4 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libaom-debugsource-3.7.1-150400.3.12.1 * aom-tools-debuginfo-3.7.1-150400.3.12.1 * libaom3-3.7.1-150400.3.12.1 * libaom-devel-3.7.1-150400.3.12.1 * aom-tools-3.7.1-150400.3.12.1 * libaom3-debuginfo-3.7.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libaom-devel-doc-3.7.1-150400.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56208.html * https://www.suse.com/security/cve/CVE-2026-56209.html * https://www.suse.com/security/cve/CVE-2026-56210.html * https://www.suse.com/security/cve/CVE-2026-56211.html * https://bugzilla.suse.com/show_bug.cgi?id=1268650 * https://bugzilla.suse.com/show_bug.cgi?id=1268651 * https://bugzilla.suse.com/show_bug.cgi?id=1268653 * https://bugzilla.suse.com/show_bug.cgi?id=1268655 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:32:21 -0000 Subject: SUSE-SU-2026:2828-1: moderate: Security update for python-idna Message-ID: <178367234152.944.11467143915650000016@530c474df1e7> # Security update for python-idna Announcement ID: SUSE-SU-2026:2828-1 Release Date: 2026-07-09T18:30:14Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2828=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2828=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2828=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-idna-3.4-150400.11.13.1 * Public Cloud Module 15-SP4 (noarch) * python311-idna-3.4-150400.11.13.1 * openSUSE Leap 15.4 (noarch) * python311-idna-3.4-150400.11.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:32:30 -0000 Subject: SUSE-SU-2026:2827-1: important: Security update for cosign Message-ID: <178367235046.944.16030519287196976101@530c474df1e7> # Security update for cosign Announcement ID: SUSE-SU-2026:2827-1 Release Date: 2026-07-09T18:28:33Z Rating: important References: * bsc#1261811 * bsc#1266049 * bsc#1267044 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33815 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33815 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-33815 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33815 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for cosign fixes the following issues * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: multiple issues when parsing HTML files (bsc#1267044). * CVE-2026-33815: memory-safety vulnerability (bsc#1261811). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: Fixed multiple issues in golang.org/x/crypto/ssh (bsc#1266049). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2827=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2827=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2827=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2827=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2827=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2827=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2827=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2827=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2827=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2827=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2827=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2827=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * cosign-bash-completion-3.1.1-150400.3.45.1 * cosign-zsh-completion-3.1.1-150400.3.45.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * openSUSE Leap 15.4 (noarch) * cosign-bash-completion-3.1.1-150400.3.45.1 * cosign-fish-completion-3.1.1-150400.3.45.1 * cosign-zsh-completion-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cosign-3.1.1-150400.3.45.1 * cosign-debuginfo-3.1.1-150400.3.45.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.1.1-150400.3.45.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.45.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33815.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1261811 * https://bugzilla.suse.com/show_bug.cgi?id=1266049 * https://bugzilla.suse.com/show_bug.cgi?id=1267044 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:32:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:32:47 -0000 Subject: SUSE-SU-2026:2826-1: important: Security update for rust-keylime Message-ID: <178367236776.944.18063758416164934977@530c474df1e7> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:2826-1 Release Date: 2026-07-09T18:21:49Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for rust-keylime fixes the following issues * Update to version 0.2.9+49. * Update openssl to 0.10.81. * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl crate (bsc#1270614). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270699). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270842). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270999). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2826=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2826=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * rust-keylime-debuginfo-0.2.9+49-150400.3.19.1 * rust-keylime-0.2.9+49-150400.3.19.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * rust-keylime-debuginfo-0.2.9+49-150400.3.19.1 * rust-keylime-0.2.9+49-150400.3.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:33:04 -0000 Subject: SUSE-SU-2026:2825-1: important: Security update for rust-keylime Message-ID: <178367238464.944.5117142255951025045@530c474df1e7> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:2825-1 Release Date: 2026-07-09T18:18:08Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for rust-keylime fixes the following issues * Update to version 0.2.9+49. * Update openssl to 0.10.81. * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust-openssl crate (bsc#1270614). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270699). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270842). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust-openssl crate (bsc#1270999). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2825=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2825=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * rust-keylime-0.2.9+49-150400.3.21.1 * rust-keylime-debuginfo-0.2.9+49-150400.3.21.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * rust-keylime-0.2.9+49-150400.3.21.1 * rust-keylime-debuginfo-0.2.9+49-150400.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:33:26 -0000 Subject: SUSE-SU-2026:2824-1: important: Security update for alloy Message-ID: <178367240602.944.5079609772536626677@530c474df1e7> # Security update for alloy Announcement ID: SUSE-SU-2026:2824-1 Release Date: 2026-07-09T18:18:01Z Rating: important References: * bsc#1260981 * bsc#1265440 * bsc#1266196 * bsc#1266654 * bsc#1267185 * bsc#1267333 * bsc#1267481 * bsc#1267485 * bsc#1267488 * bsc#1267489 * bsc#1267811 Cross-References: * CVE-2026-10722 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33532 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41889 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-45678 * CVE-2026-45682 * CVE-2026-45685 * CVE-2026-45686 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-10722 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10722 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10722 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10722 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-10722 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33532 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33532 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33532 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41889 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41889 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41889 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41889 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45678 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45682 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45685 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45686 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 27 vulnerabilities can now be installed. ## Description: This update for alloy fixes the following issues * CVE-2026-10722: github.com/cilium/ebpf: BTF string offset boundary check can lead to crash when parsing malformed ELF/BTF input (bsc#1267811). * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267185). * CVE-2026-33532: denial of service via deeply nested YAML document parsing (bsc#1260981). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1266196). * CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: SQL injection when placeholders in dollar-quoted string literals are used in the SQL query (bsc#1265440). * CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267333). * CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are processed (bsc#1267481). * CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485). * CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS (bsc#1267488). * CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process and cause denial of service (bsc#1267489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2824=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * alloy-1.17.1-150700.15.23.1 * alloy-debuginfo-1.17.1-150700.15.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10722.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33532.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41889.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-45678.html * https://www.suse.com/security/cve/CVE-2026-45682.html * https://www.suse.com/security/cve/CVE-2026-45685.html * https://www.suse.com/security/cve/CVE-2026-45686.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1260981 * https://bugzilla.suse.com/show_bug.cgi?id=1265440 * https://bugzilla.suse.com/show_bug.cgi?id=1266196 * https://bugzilla.suse.com/show_bug.cgi?id=1266654 * https://bugzilla.suse.com/show_bug.cgi?id=1267185 * https://bugzilla.suse.com/show_bug.cgi?id=1267333 * https://bugzilla.suse.com/show_bug.cgi?id=1267481 * https://bugzilla.suse.com/show_bug.cgi?id=1267485 * https://bugzilla.suse.com/show_bug.cgi?id=1267488 * https://bugzilla.suse.com/show_bug.cgi?id=1267489 * https://bugzilla.suse.com/show_bug.cgi?id=1267811 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:33:33 -0000 Subject: SUSE-SU-2026:2823-1: important: Security update for helm Message-ID: <178367241323.944.11728142827123706507@530c474df1e7> # Security update for helm Announcement ID: SUSE-SU-2026:2823-1 Release Date: 2026-07-09T18:14:15Z Rating: important References: * bsc#1266598 * bsc#1270127 Cross-References: * CVE-2026-39821 * CVE-2026-48978 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues * Update to version 3.21.2. * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266598). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2823=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2823=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2823=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2823=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2823=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2823=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2823=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2823=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2823=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2823=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2823=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-3.21.2-150000.1.80.1 * helm-debuginfo-3.21.2-150000.1.80.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.80.1 * helm-bash-completion-3.21.2-150000.1.80.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.2-150000.1.80.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1266598 * https://bugzilla.suse.com/show_bug.cgi?id=1270127 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:33:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:33:56 -0000 Subject: SUSE-SU-2026:2822-1: important: Security update for gnutls Message-ID: <178367243646.944.2509264313893657712@530c474df1e7> # Security update for gnutls Announcement ID: SUSE-SU-2026:2822-1 Release Date: 2026-07-09T18:07:13Z Rating: important References: * bsc#1257960 * bsc#1263704 * bsc#1263705 * bsc#1263707 * bsc#1263708 * bsc#1263709 * bsc#1263710 * bsc#1263711 * bsc#1263712 * bsc#1263713 * bsc#1263714 * bsc#1263715 Cross-References: * CVE-2025-14831 * CVE-2026-33845 * CVE-2026-33846 * CVE-2026-3833 * CVE-2026-42009 * CVE-2026-42010 * CVE-2026-42011 * CVE-2026-42012 * CVE-2026-42013 * CVE-2026-42014 * CVE-2026-42015 * CVE-2026-5260 CVSS scores: * CVE-2025-14831 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-14831 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-14831 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33845 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33845 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-33845 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33845 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-33845 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33846 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3833 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3833 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42009 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42009 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42009 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42009 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42010 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42010 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42010 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42010 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42010 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-42011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42011 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42012 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42012 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-42012 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-42013 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42013 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-42015 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42015 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-42015 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5260 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5260 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5260 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for gnutls fixes the following issues * CVE-2025-14831: excessive resource consumption when verifying specially crafted malicious certificates containing a large number of name constraints and SANs (bsc#1257960). * CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707). * CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715). * CVE-2026-33845: integer overflow and heap overrun when parsing fragments with zero length and non-zero offset during DTLS handshake (bsc#1263704). * CVE-2026-33846: heap overwrite during DTLS handshake fragment reassembly due to missing validations and checks (bsc#1263705). * CVE-2026-42009: undefined behavior resulting in a DoS when handling DTLS packets with duplicate sequence numbers (bsc#1263708). * CVE-2026-42010: authentication bypass when processing a PSK username with a NUL-character (bsc#1263709). * CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710). * CVE-2026-42012: spoofing of legitimate services and sensitive information interception via specially crafted certificates containing URIs or SRV SANs. (bsc#1263711). * CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712). * CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713). * CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2822=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2822=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgnutls30-3.7.3-150400.24.2 * gnutls-3.7.3-150400.24.2 * libgnutls30-hmac-3.7.3-150400.24.2 * libgnutls30-debuginfo-3.7.3-150400.24.2 * gnutls-debuginfo-3.7.3-150400.24.2 * gnutls-debugsource-3.7.3-150400.24.2 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgnutls30-3.7.3-150400.24.2 * gnutls-3.7.3-150400.24.2 * libgnutls30-hmac-3.7.3-150400.24.2 * libgnutls30-debuginfo-3.7.3-150400.24.2 * gnutls-debuginfo-3.7.3-150400.24.2 * gnutls-debugsource-3.7.3-150400.24.2 ## References: * https://www.suse.com/security/cve/CVE-2025-14831.html * https://www.suse.com/security/cve/CVE-2026-33845.html * https://www.suse.com/security/cve/CVE-2026-33846.html * https://www.suse.com/security/cve/CVE-2026-3833.html * https://www.suse.com/security/cve/CVE-2026-42009.html * https://www.suse.com/security/cve/CVE-2026-42010.html * https://www.suse.com/security/cve/CVE-2026-42011.html * https://www.suse.com/security/cve/CVE-2026-42012.html * https://www.suse.com/security/cve/CVE-2026-42013.html * https://www.suse.com/security/cve/CVE-2026-42014.html * https://www.suse.com/security/cve/CVE-2026-42015.html * https://www.suse.com/security/cve/CVE-2026-5260.html * https://bugzilla.suse.com/show_bug.cgi?id=1257960 * https://bugzilla.suse.com/show_bug.cgi?id=1263704 * https://bugzilla.suse.com/show_bug.cgi?id=1263705 * https://bugzilla.suse.com/show_bug.cgi?id=1263707 * https://bugzilla.suse.com/show_bug.cgi?id=1263708 * https://bugzilla.suse.com/show_bug.cgi?id=1263709 * https://bugzilla.suse.com/show_bug.cgi?id=1263710 * https://bugzilla.suse.com/show_bug.cgi?id=1263711 * https://bugzilla.suse.com/show_bug.cgi?id=1263712 * https://bugzilla.suse.com/show_bug.cgi?id=1263713 * https://bugzilla.suse.com/show_bug.cgi?id=1263714 * https://bugzilla.suse.com/show_bug.cgi?id=1263715 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:34:02 -0000 Subject: SUSE-SU-2026:2821-1: moderate: Security update for python-sqlparse Message-ID: <178367244226.944.5164692561314168479@530c474df1e7> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:2821-1 Release Date: 2026-07-09T18:05:57Z Rating: moderate References: * bsc#1268597 Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that has one security fix can now be installed. ## Description: This update for python-sqlparse fixes the following issue * Fixed an issue where formatting list of tuples leads to denial of service (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2821=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python2-sqlparse-0.2.4-150100.6.8.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:34:07 -0000 Subject: SUSE-SU-2026:2820-1: important: Security update for GraphicsMagick Message-ID: <178367244779.944.17614985371095052170@530c474df1e7> # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:2820-1 Release Date: 2026-07-09T18:01:15Z Rating: important References: * bsc#1269891 Cross-References: * CVE-2026-13606 CVSS scores: * CVE-2026-13606 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue * CVE-2026-13606: crafted Photo CD (PCD) file can cause memory corruption (bsc#1269891). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2820=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2820=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-devel-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.33.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick++-devel-1.3.42-150600.3.33.1 * perl-GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick3-config-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.33.1 * GraphicsMagick-debugsource-1.3.42-150600.3.33.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-devel-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.33.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.33.1 * GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick++-devel-1.3.42-150600.3.33.1 * perl-GraphicsMagick-1.3.42-150600.3.33.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.33.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.33.1 * libGraphicsMagick3-config-1.3.42-150600.3.33.1 * GraphicsMagick-debugsource-1.3.42-150600.3.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13606.html * https://bugzilla.suse.com/show_bug.cgi?id=1269891 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:34:15 -0000 Subject: SUSE-SU-2026:2819-1: moderate: Security update for python-Django Message-ID: <178367245585.944.6615955702097463144@530c474df1e7> # Security update for python-Django Announcement ID: SUSE-SU-2026:2819-1 Release Date: 2026-07-09T17:12:22Z Rating: moderate References: * bsc#1271029 * bsc#1271030 Cross-References: * CVE-2026-48588 * CVE-2026-53877 CVSS scores: * CVE-2026-48588 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48588 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48588 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48588 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-53877 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53877 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-53877 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Django fixes the following issues: * CVE-2026-48588: potential exposure of private data via cached `Set-Cookie` response (bsc#1271029). * CVE-2026-53877: information disclosure via 32-byte heap buffer overread in `GDALRaster` (bsc#1271030). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2819=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2819=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python311-Django-4.2.11-150600.3.62.1 * openSUSE Leap 15.6 (noarch) * python311-Django-4.2.11-150600.3.62.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48588.html * https://www.suse.com/security/cve/CVE-2026-53877.html * https://bugzilla.suse.com/show_bug.cgi?id=1271029 * https://bugzilla.suse.com/show_bug.cgi?id=1271030 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:34:27 -0000 Subject: SUSE-SU-2026:2818-1: important: Security update for go1.26 Message-ID: <178367246764.944.6930112172351372265@530c474df1e7> # Security update for go1.26 Announcement ID: SUSE-SU-2026:2818-1 Release Date: 2026-07-09T17:09:48Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities, contains one feature and has three security fixes can now be installed. ## Description: This update for go1.26 fixes the following issues * Update to version go1.26.5 (bsc#1255111) * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2818=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2818=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2818=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2818=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2818=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2818=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2818=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2818=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2818=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2818=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2818=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.26-1.26.5-150000.1.18.1 * go1.26-doc-1.26.5-150000.1.18.1 * go1.26-race-1.26.5-150000.1.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 08:34:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 08:34:48 -0000 Subject: SUSE-SU-2026:2817-1: important: Security update for go1.25 Message-ID: <178367248842.944.5451113279841794177@530c474df1e7> # Security update for go1.25 Announcement ID: SUSE-SU-2026:2817-1 Release Date: 2026-07-09T17:08:22Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities, contains one feature and has three security fixes can now be installed. ## Description: This update for go1.25 fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2817=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2817=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2817=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2817=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2817=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2817=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2817=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2817=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2817=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2817=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2817=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.25-1.25.12-150000.1.44.1 * go1.25-race-1.25.12-150000.1.44.1 * go1.25-doc-1.25.12-150000.1.44.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:30:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:30:38 -0000 Subject: SUSE-SU-2026:22536-1: important: Security update for update 5.1.3 for SUSE_Multi-Linux_Manager Client Tools and Salt Bundle Message-ID: <178368663813.1052.11794901749761219853@5ed4f61072e9> # Security update for update 5.1.3 for SUSE_Multi-Linux_Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22536-1 Release Date: 2026-06-15T07:20:25Z Rating: important References: * bsc#1250367 * bsc#1252548 * bsc#1252964 * bsc#1254154 * bsc#1254619 * bsc#1254629 * bsc#1257447 * bsc#1257660 * bsc#1257831 * bsc#1257941 * bsc#1258015 * bsc#1258418 * bsc#1258927 * bsc#1258957 * bsc#1259208 * bsc#1259553 * bsc#1259554 Cross-References: * CVE-2026-31958 CVSS scores: * CVE-2026-31958 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves one vulnerability and has 16 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-lusitaniae-apache_exporter: * Internal changes to fix build issues with no impact for customers uyuni-tools: * version 5.1.26-0 * Fixed applying PTF with images from RPMs (bsc#1252548) * Fixed Ssl Key file that can miss if CA password is blank (bsc#1254154) * mgrpxy ssh tuning should happens before crypto policies (bsc#1254619) * Fixed default value for helm registry (bsc#1258927). * Removed hub register command * Optimized postgres migration disk space usage (bsc#1257447) * Added continuous database backup support (bsc#1250367) * Explicitly start proxy pods after operations (bsc#1258015) * Use static supportconfig name to avoid dynamic search (bsc#1257941) * Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) * Show where final tarball was generated (bsc#1259208) * Set proxy config file permissions (bsc#1257660) * version 5.1.25-0 * If PTF image doesn't exists, use the current service image (bsc#1258418) venv-salt-minion: * Security issues fixed: * CVE-2026-31958: Security patch for Salt vendored tornado: Added limits on multipart form data parsing (bsc#1259554) * Added x86_64_v2 as a possible rpm package architecture * Make users with backslash working for salt-ssh (bsc#1254629) * Fixed ansible.playbooks extra-vars quoting (bsc#1257831) * Fixed virtualenv call in test helper to use proper python version * Fixed the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957) * Fixed the typo causing buiding EL9 bundle without binary dependencies ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-64=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-5.1.26-1.1 * mgrctl-lang-5.1.26-1.1 * mgrctl-bash-completion-5.1.26-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-5.1.26-1.1 * mgrctl-debuginfo-5.1.26-1.1 * venv-salt-minion-3006.0-11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31958.html * https://bugzilla.suse.com/show_bug.cgi?id=1250367 * https://bugzilla.suse.com/show_bug.cgi?id=1252548 * https://bugzilla.suse.com/show_bug.cgi?id=1252964 * https://bugzilla.suse.com/show_bug.cgi?id=1254154 * https://bugzilla.suse.com/show_bug.cgi?id=1254619 * https://bugzilla.suse.com/show_bug.cgi?id=1254629 * https://bugzilla.suse.com/show_bug.cgi?id=1257447 * https://bugzilla.suse.com/show_bug.cgi?id=1257660 * https://bugzilla.suse.com/show_bug.cgi?id=1257831 * https://bugzilla.suse.com/show_bug.cgi?id=1257941 * https://bugzilla.suse.com/show_bug.cgi?id=1258015 * https://bugzilla.suse.com/show_bug.cgi?id=1258418 * https://bugzilla.suse.com/show_bug.cgi?id=1258927 * https://bugzilla.suse.com/show_bug.cgi?id=1258957 * https://bugzilla.suse.com/show_bug.cgi?id=1259208 * https://bugzilla.suse.com/show_bug.cgi?id=1259553 * https://bugzilla.suse.com/show_bug.cgi?id=1259554 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:31:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:31:23 -0000 Subject: SUSE-SU-2026:22535-1: important: Security update 5.1.2 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178368668373.1052.14360621024508633341@5ed4f61072e9> # Security update 5.1.2 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22535-1 Release Date: 2026-06-15T07:20:17Z Rating: important References: * bsc#1175946 * bsc#1227207 * bsc#1240532 * bsc#1246130 * bsc#1247644 * bsc#1247721 * bsc#1248848 * bsc#1249400 * bsc#1249434 * bsc#1250520 * bsc#1250940 * bsc#1250976 * bsc#1250981 * bsc#1251044 * bsc#1251138 * bsc#1251776 * bsc#1252244 * bsc#1252285 * bsc#1253282 * bsc#1253347 * bsc#1253738 * bsc#1253966 * bsc#1254325 * bsc#1254478 * bsc#1254903 * bsc#1254904 * bsc#1254905 * bsc#1255781 * jsc#MSQA-1040 Cross-References: * CVE-2025-13836 * CVE-2025-62348 * CVE-2025-62349 CVSS scores: * CVE-2025-13836 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-13836 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62348 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-62348 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62348 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62349 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-62349 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-62349 ( NVD ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62349 ( NVD ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves three vulnerabilities, contains one feature and has 25 fixes can now be installed. ## Description: This update fixes the following issues: uyuni-tools: * Version 5.1.24-0 * Actually use the --dbupgrade-tag parameter when computing the image URL (bsc#1249400) * Handle CA files with symlinks during migration (bsc#1251044) * Adjust traefik exposed configuration for chart v27+ (bsc#1247721) * Fix systemd object initialization in server rename. (bsc#1250981) * Add SSL secrets to the db setup container during migration. (bsc#1250976) * Fix images handling in mgrpxy support ptf (bsc#1250940) * Fix helm upgrade parameters (bsc#1253966) * Detect custom apache and squid config in the /etc/uyuni/proxy folder * Add ssh tuning to configure sshd (bsc#1253738) * Move the SSL checks at the begining of the migration * Remove cgroup mount for podman containers (bsc#1253347) * Convert the traefik install time to local time (bsc#1251138) * During migration, krb5.conf.d should be copied in /etc/rhn (bsc#1254478) * Read env var from http conf file (bsc#1253282) * Add --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * Deprecate --registry * Unify backup create and restore dryrun option case * Fix calling of squid -z in mgrpxy cache clear (bsc#1247644) * Always start database container even if enabled * Remove extra ipv6 mapping and nftables workaround (bsc#1248848) * Remove old PostgreSQL exporter environment file before migration * Support config command parse correctly supportconfig output (bsc#1255781) * Version 5.1.23-0 * Update the default tag * Version 5.1.22-0 * Fix cobbler config migration to standalone files * Fix generated DB certificate subject alternate names * Version 5.1.21-0 * Remove extraneous quotes when getting the running image (bsc#1249434) venv-salt-minion: * Security issues fixed: * CVE-2025-67724: Fixed missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: Fixed DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: Fixed HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * Fixed TLS and x509 modules for OSes with older cryptography module * Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd * Fixed payload signature verification on Tumbleweed (bsc#1251776) * Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) * Made syntax in httputil_test compatible with Python 3.6 * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Speed up wheel key.finger call (bsc#1240532) * Improved utils.find_json function (bsc#1246130) * Extended warn_until period to 2027 golang-github-QubitProducts-exporter_exporter: * New package at version 0.4.0 golang-github-lusitaniae-apache_exporter: * Build without apparmor for openSUSE Leap 16, SLES 16 or newer * Require Go 1.23 for building * Update to version 1.0.10 * Update github.com/prometheus/client_golang to 1.21.1 * Update github.com/prometheus/common to 0.63.0 * Update github.com/prometheus/exporter-toolkit to 0.14.0 * Update to version 1.0.9 * Update github.com/prometheus/client_golang to 1.20.4 * Update github.com/prometheus/common to 0.59.1 * Update github.com/prometheus/exporter-toolkit to 0.13.0 * Migrate logging to log/slog * Fix signal handler logging golang-github-prometheus-node_exporter: * Non-customer-facing optimization around source building ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-63=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-lang-5.1.24-1.1 * mgrctl-zsh-completion-5.1.24-1.1 * mgrctl-bash-completion-5.1.24-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-1.9.1-2.1 * mgrctl-debuginfo-5.1.24-1.1 * venv-salt-minion-3006.0-10.1 * mgrctl-5.1.24-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.1-2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13836.html * https://www.suse.com/security/cve/CVE-2025-62348.html * https://www.suse.com/security/cve/CVE-2025-62349.html * https://bugzilla.suse.com/show_bug.cgi?id=1175946 * https://bugzilla.suse.com/show_bug.cgi?id=1227207 * https://bugzilla.suse.com/show_bug.cgi?id=1240532 * https://bugzilla.suse.com/show_bug.cgi?id=1246130 * https://bugzilla.suse.com/show_bug.cgi?id=1247644 * https://bugzilla.suse.com/show_bug.cgi?id=1247721 * https://bugzilla.suse.com/show_bug.cgi?id=1248848 * https://bugzilla.suse.com/show_bug.cgi?id=1249400 * https://bugzilla.suse.com/show_bug.cgi?id=1249434 * https://bugzilla.suse.com/show_bug.cgi?id=1250520 * https://bugzilla.suse.com/show_bug.cgi?id=1250940 * https://bugzilla.suse.com/show_bug.cgi?id=1250976 * https://bugzilla.suse.com/show_bug.cgi?id=1250981 * https://bugzilla.suse.com/show_bug.cgi?id=1251044 * https://bugzilla.suse.com/show_bug.cgi?id=1251138 * https://bugzilla.suse.com/show_bug.cgi?id=1251776 * https://bugzilla.suse.com/show_bug.cgi?id=1252244 * https://bugzilla.suse.com/show_bug.cgi?id=1252285 * https://bugzilla.suse.com/show_bug.cgi?id=1253282 * https://bugzilla.suse.com/show_bug.cgi?id=1253347 * https://bugzilla.suse.com/show_bug.cgi?id=1253738 * https://bugzilla.suse.com/show_bug.cgi?id=1253966 * https://bugzilla.suse.com/show_bug.cgi?id=1254325 * https://bugzilla.suse.com/show_bug.cgi?id=1254478 * https://bugzilla.suse.com/show_bug.cgi?id=1254903 * https://bugzilla.suse.com/show_bug.cgi?id=1254904 * https://bugzilla.suse.com/show_bug.cgi?id=1254905 * https://bugzilla.suse.com/show_bug.cgi?id=1255781 * https://jira.suse.com/browse/MSQA-1040 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:31:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:31:53 -0000 Subject: SUSE-SU-2026:22534-1: important: Security update 5.0.8 for Multi-Linux Manager Client Tools, Salt Bundle and Salt Message-ID: <178368671319.1052.17522317500911931918@5ed4f61072e9> # Security update 5.0.8 for Multi-Linux Manager Client Tools, Salt Bundle and Salt Announcement ID: SUSE-SU-2026:22534-1 Release Date: 2026-06-03T12:47:13Z Rating: important References: * bsc#1252964 * bsc#1254619 * bsc#1254629 * bsc#1254900 * bsc#1257583 * bsc#1257831 * bsc#1257941 * bsc#1258927 * bsc#1258957 * bsc#1259208 * bsc#1259554 * bsc#1259700 * bsc#1259804 * bsc#1259808 * bsc#1261810 Cross-References: * CVE-2026-27448 * CVE-2026-27459 * CVE-2026-31958 CVSS scores: * CVE-2026-27448 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27448 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27448 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27448 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-27459 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-27459 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-27459 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-27459 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27459 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31958 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31958 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31958 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-31958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves three vulnerabilities and has 12 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-node_exporter: * Version 1.10.2: * meminfo: Fix typo in Zswap metric name * Version 1.10.1: * filesystem: Fix mount points being collected multiple times * filesystem: Refactor mountinfo parsing (bsc#1261810) * meminfo: Add Zswap/Zswapped metrics * Version 1.10.0: * Changes: * mdadm: Use sysfs for RAID metrics * filesystem: Add erofs in default excluded fs * tcpstat: Use std lib binary.NativeEndian * New Features: * pcidevice: Add new collector for PCIe devices * AIX: Add more metrics * systemd: Add Virtualization metrics * swaps: Add new collector * Enhancements: * wifi: Add packet received and transmitted metrics * filesystem: Take super options into account for read-only * pcidevice: Add additional metrics * perf: Add tlb_data metrics * Bugs fixed: * interrupts: Fix OpenBSD interrupt device parsing * diskstats: Simplify condition * thermal: Sanitize darwin thermal strings * filesystem: Fix Darwin collector cgo memory leak * cpufreq: Fix: collector enable * ethtool: Fix returning 0 for sanitized metrics * netdev: Fix Darwin netdev i/o bytes metric * systemd: Fix logging race * filesystem: Fix duplicate Darwin CGO import salt: * Security issues fixed: * CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) * Other updates and bugfixes: * Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Fixed testsuite failures * Make users with backslash working for salt-ssh (bsc#1254629) * Fixed ansible.playbooks extra-vars quoting (bsc#1257831) * Fixed virtualenv call in test helper to use proper python version uyuni-tools: * Version 0.1.39-0: * mgrpxy ssh tuning should happen before crypto policies (bsc#1254619) * Fixed default value for helm registry (bsc#1258927). * Use static supportconfig name to avoid dynamic search (bsc#1257941) * Do not nest multiple tarball files and instead collect all files into one tarball (bsc#1252964) * Show where final tarball was generated (bsc#1259208) venv-salt-minion: * Security issues fixed: * CVE-2026-31958: tornado: Fixed parsing large multipart bodies with many parts can cause a denial of service (bsc#1259554) * CVE-2026-27459: pyOpenSSL: Fixed issue with large cookie value that can lead to a buffer overflow (bsc#1259808) * CVE-2026-27448: pyOpenSSL: Fixed unhandled exception can result in connection not being cancelled (bsc#1259804) * Other updates and bugfixes: * Use non vendored Tornado with Python 3.11 (bsc#1257583, bsc#1259700) * Hardened Tornado from invalid HTTP reason phrases * Read full URI from ldap pillar config (bsc#1254900) * Make users with backslash work for `salt-ssh` (bsc#1254629). * Fixed `ansible.playbooks` `extra-vars` quoting (bsc#1257831), * Fixed `virtualenv` call in test helper to use proper Python version. * Fixed the issue preventing SELinux profile to be loaded on SLES 16 deployed using cloud images (bsc#1258957) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6740=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.39-1.1 * mgrctl-lang-0.1.39-1.1 * mgrctl-bash-completion-0.1.39-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.39-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.10.2-1.1 * venv-salt-minion-3006.0-11.1 * mgrctl-0.1.39-1.1 * golang-github-prometheus-node_exporter-1.10.2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27448.html * https://www.suse.com/security/cve/CVE-2026-27459.html * https://www.suse.com/security/cve/CVE-2026-31958.html * https://bugzilla.suse.com/show_bug.cgi?id=1252964 * https://bugzilla.suse.com/show_bug.cgi?id=1254619 * https://bugzilla.suse.com/show_bug.cgi?id=1254629 * https://bugzilla.suse.com/show_bug.cgi?id=1254900 * https://bugzilla.suse.com/show_bug.cgi?id=1257583 * https://bugzilla.suse.com/show_bug.cgi?id=1257831 * https://bugzilla.suse.com/show_bug.cgi?id=1257941 * https://bugzilla.suse.com/show_bug.cgi?id=1258927 * https://bugzilla.suse.com/show_bug.cgi?id=1258957 * https://bugzilla.suse.com/show_bug.cgi?id=1259208 * https://bugzilla.suse.com/show_bug.cgi?id=1259554 * https://bugzilla.suse.com/show_bug.cgi?id=1259700 * https://bugzilla.suse.com/show_bug.cgi?id=1259804 * https://bugzilla.suse.com/show_bug.cgi?id=1259808 * https://bugzilla.suse.com/show_bug.cgi?id=1261810 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:32:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:32:18 -0000 Subject: SUSE-SU-2026:22533-1: important: Security update 5.0.7 for Multi-Linux Manager for Client Tools, Salt Bundle, Salt Message-ID: <178368673876.1052.9888855998177622203@5ed4f61072e9> # Security update 5.0.7 for Multi-Linux Manager for Client Tools, Salt Bundle, Salt Announcement ID: SUSE-SU-2026:22533-1 Release Date: 2026-03-24T06:26:01Z Rating: important References: * bsc#1240532 * bsc#1246130 * bsc#1253347 * bsc#1253738 * bsc#1254256 * bsc#1254257 * bsc#1254325 * bsc#1254589 * bsc#1254903 * bsc#1254904 * bsc#1254905 * bsc#1255781 * bsc#1256803 * bsc#1257941 Cross-References: * CVE-2025-62348 * CVE-2025-62349 * CVE-2025-67724 * CVE-2025-67725 * CVE-2025-67726 CVSS scores: * CVE-2025-62348 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-62348 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62348 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62349 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-62349 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-62349 ( NVD ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62349 ( NVD ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-67724 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-67724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2025-67724 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2025-67725 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67725 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-67726 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-67726 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves five vulnerabilities and has nine fixes can now be installed. ## Description: This update for fixes the following issues: golang-github-prometheus-node_exporter: * Require gcc11-c++ for building with SLE 12 uyuni-tools: * Version 0.1.38-0: * Fixed cobbler config migration to standalone files (bsc#1256803) * Detect custom apache and squid config in the /etc/uyuni/proxy folder * Added ssh tuning to configure sshd (bsc#1253738) * Ignore supportconfig errors (bsc#1255781) * Bumped the default image tag to 5.0.7 * Remove cgroup mount for podman containers (bsc#1253347) * Registry flag can be a string (bsc#1254589) * Use static supportconfig name to avoid dynamic search (bsc#1257941) venv-salt-minion: * Security issues fixed: * CVE-2025-67724: missing validation of supplied reason phrase (bsc#1254903) * CVE-2025-67725: fix DoS via malicious HTTP request (bsc#1254905) * CVE-2025-67726: fix HTTP header parameter parsing algorithm (bsc#1254904) * CVE-2025-62349: Add minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Junos module yaml loader fix (bsc#1254256) * Fixed the typo causing buiding EL9 bundle without binary dependencies * Make syntax in httputil_test compatible with Python 3.6 * Fixed KeyError in postgres module with PostgreSQL 17 (bsc#1254325) * Use internal deb classes instead of external aptsource lib * Speed up wheel key.finger call (bsc#1240532) * Simplify and speed up utils.find_json function (bsc#1246130) ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6635=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.38-1.1 * mgrctl-lang-0.1.38-1.1 * mgrctl-bash-completion-0.1.38-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * golang-github-prometheus-node_exporter-1.9.1-2.1 * venv-salt-minion-3006.0-10.1 * mgrctl-debuginfo-0.1.38-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.1-2.1 * mgrctl-0.1.38-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-62348.html * https://www.suse.com/security/cve/CVE-2025-62349.html * https://www.suse.com/security/cve/CVE-2025-67724.html * https://www.suse.com/security/cve/CVE-2025-67725.html * https://www.suse.com/security/cve/CVE-2025-67726.html * https://bugzilla.suse.com/show_bug.cgi?id=1240532 * https://bugzilla.suse.com/show_bug.cgi?id=1246130 * https://bugzilla.suse.com/show_bug.cgi?id=1253347 * https://bugzilla.suse.com/show_bug.cgi?id=1253738 * https://bugzilla.suse.com/show_bug.cgi?id=1254256 * https://bugzilla.suse.com/show_bug.cgi?id=1254257 * https://bugzilla.suse.com/show_bug.cgi?id=1254325 * https://bugzilla.suse.com/show_bug.cgi?id=1254589 * https://bugzilla.suse.com/show_bug.cgi?id=1254903 * https://bugzilla.suse.com/show_bug.cgi?id=1254904 * https://bugzilla.suse.com/show_bug.cgi?id=1254905 * https://bugzilla.suse.com/show_bug.cgi?id=1255781 * https://bugzilla.suse.com/show_bug.cgi?id=1256803 * https://bugzilla.suse.com/show_bug.cgi?id=1257941 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:33:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:33:03 -0000 Subject: SUSE-SU-2026:22532-1: important: Security update 5.0.6 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Message-ID: <178368678390.1052.9902782215787585011@5ed4f61072e9> # Security update 5.0.6 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Announcement ID: SUSE-SU-2026:22532-1 Release Date: 2025-12-16T07:28:05Z Rating: important References: * bsc#1227207 * bsc#1243611 * bsc#1243704 * bsc#1244027 * bsc#1244127 * bsc#1244534 * bsc#1245099 * bsc#1245740 * bsc#1246068 * bsc#1246320 * bsc#1246553 * bsc#1246662 * bsc#1246738 * bsc#1246789 * bsc#1246882 * bsc#1246906 * bsc#1246925 * bsc#1247688 * bsc#1247721 * bsc#1250520 * bsc#1250755 * bsc#1251044 * bsc#1251138 * bsc#1251776 * bsc#1252244 * bsc#1252285 * bsc#1254256 * bsc#1254257 Cross-References: * CVE-2025-62348 * CVE-2025-62349 CVSS scores: * CVE-2025-62348 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-62348 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62348 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-62349 ( SUSE ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2025-62349 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L * CVE-2025-62349 ( NVD ): 7.5 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62349 ( NVD ): 6.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:L Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves two vulnerabilities and has 26 fixes can now be installed. ## Description: This update fixes the following issues: salt: * Security issues fixed: * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * Backport security fixes for vendored tornado * BDSA-2024-3438 * BDSA-2024-3439 * BDSA-2024-9026 * Other changes and bugs fixed: * Fixed TLS and x509 modules for OSes with older cryptography module * Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd * Fixed payload signature verification on Tumbleweed (bsc#1251776) * Fixed broken symlink on migration to Leap 16.0 (bsc#1250755) * Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) * Fixed functional.states.test_user for SLES 16 and Micro systems * Fixed the tests failing on AlmaLinux 10 and other clones * Improved SL Micro 6.2 detection with grains * Require Python dependencies only for used Python version * Reverted requirement of M2Crypto >= 0.44.0 for SUSE Family distros * Set python-CherryPy as required for python-salt-testsuite uyuni-tools: * Version 0.1.37-0 * Added --registry-host, --registry-user and --registry-password to pull images from an authenticate registry * Added a lowercase version of --logLevel (bsc#1243611) * Added migration for server monitoring configuration (bsc#1247688) * Added SLE15SP7 to buildin productmap * Adjusted traefik exposed configuration for chart v27+ (bsc#1247721) * Automatically get up-to-date systemid file on salt based proxy hosts (bsc#1246789) * Check for restorecon presence before calling (bsc#1246925) * Convert the traefik install time to local time (bsc#1251138) * Deprecated --registry * Do not require backups to be at the same location for restoring (bsc#1246906) * Do not use sudo when running as a root user (bsc#1246882) * Fixed channel override for distro copy * Fixed loading product map from mgradm configuration file (bsc#1246068) * Fixed recomputing proxy images when installing a ptf or test (bsc#1246553) * Handle CA files with symlinks during migration (bsc#1251044) * Migrate custom auto installation snippets (bsc#1246320) * Run smdba and reindex only during migration (bsc#1244534) * Stop executing scripts in temporary folder (bsc#1243704) * Support config: collect podman inspect for hub container(bsc#1245099) * Use new dedicated path for Cobbler settings (bsc#1244027) * Version 0.1.36-0 * Bump the default image tag to 5.0.5.1 * Version 0.1.35-0 * Restore SELinux contexts for restored backup volumes (bsc#1244127) * Version 0.1.34-0 * Fixed mgradm backup create handling of images and systemd files (bsc#1246738) * Version 0.1.33-0 * Restore volumes using tar instead of podman import (bsc#1244127) * Version 0.1.32-0 * Fixed version compare by backport from main (bsc#1246662) venv-salt-minion: * Security issues fixed: * CVE-2025-62349: Added minimum_auth_version to enforce security (bsc#1254257) * CVE-2025-62348: Fixed Junos module yaml loader (bsc#1254256) * Backport security fixes for vendored tornado * BDSA-2024-3438 * BDSA-2024-3439 * BDSA-2024-9026 * Other changes and bugs fixed: * Added `minion_legacy_req_warnings` option to avoid noisy warnings * Fixed TLS and x509 modules for OSes with older cryptography module * Fixed Salt for Python > 3.11 (bsc#1252285) (bsc#1252244) * Use external tornado on Python > 3.11 * Make tls and x509 to use python-cryptography * Remove usage of spwd * Filter out zero-length check as the empty files are expected there * Filter out env-script-interpreter for ssh-id-wrapper as not used with the Salt Bundle, but present inside the salt module * Fixed functional.states.test_user for SLES 16 and Micro systems * Fixed known_hosts error on gitfs (bsc#1250520) (bsc#1227207) * Fixed payload signature verification on Tumbleweed (bsc#1251776) * Fixed the tests failing on AlmaLinux 10 and other clones * Improve SL Micro 6.2 detection with grains * Removed unused activate script (bsc#1245740) * Use more strict way to Fixed shebang in the bundle scripts * Use versioned python interpreter for salt-ssh ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6535=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-0.1.37-1.1 * mgrctl-debuginfo-0.1.37-1.1 * venv-salt-minion-3006.0-9.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.37-1.1 * mgrctl-lang-0.1.37-1.1 * mgrctl-bash-completion-0.1.37-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-62348.html * https://www.suse.com/security/cve/CVE-2025-62349.html * https://bugzilla.suse.com/show_bug.cgi?id=1227207 * https://bugzilla.suse.com/show_bug.cgi?id=1243611 * https://bugzilla.suse.com/show_bug.cgi?id=1243704 * https://bugzilla.suse.com/show_bug.cgi?id=1244027 * https://bugzilla.suse.com/show_bug.cgi?id=1244127 * https://bugzilla.suse.com/show_bug.cgi?id=1244534 * https://bugzilla.suse.com/show_bug.cgi?id=1245099 * https://bugzilla.suse.com/show_bug.cgi?id=1245740 * https://bugzilla.suse.com/show_bug.cgi?id=1246068 * https://bugzilla.suse.com/show_bug.cgi?id=1246320 * https://bugzilla.suse.com/show_bug.cgi?id=1246553 * https://bugzilla.suse.com/show_bug.cgi?id=1246662 * https://bugzilla.suse.com/show_bug.cgi?id=1246738 * https://bugzilla.suse.com/show_bug.cgi?id=1246789 * https://bugzilla.suse.com/show_bug.cgi?id=1246882 * https://bugzilla.suse.com/show_bug.cgi?id=1246906 * https://bugzilla.suse.com/show_bug.cgi?id=1246925 * https://bugzilla.suse.com/show_bug.cgi?id=1247688 * https://bugzilla.suse.com/show_bug.cgi?id=1247721 * https://bugzilla.suse.com/show_bug.cgi?id=1250520 * https://bugzilla.suse.com/show_bug.cgi?id=1250755 * https://bugzilla.suse.com/show_bug.cgi?id=1251044 * https://bugzilla.suse.com/show_bug.cgi?id=1251138 * https://bugzilla.suse.com/show_bug.cgi?id=1251776 * https://bugzilla.suse.com/show_bug.cgi?id=1252244 * https://bugzilla.suse.com/show_bug.cgi?id=1252285 * https://bugzilla.suse.com/show_bug.cgi?id=1254256 * https://bugzilla.suse.com/show_bug.cgi?id=1254257 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:33:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:33:35 -0000 Subject: SUSE-SU-2026:22531-1: important: Security update 5.1.1 for Multi-Linux Manager Client Tools and Salt Bundle Message-ID: <178368681536.1052.14915755494014901219@5ed4f61072e9> # Security update 5.1.1 for Multi-Linux Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22531-1 Release Date: 2025-10-23T15:29:04Z Rating: important References: * bsc#1229825 * bsc#1243331 * bsc#1243611 * bsc#1243704 * bsc#1244027 * bsc#1244127 * bsc#1245099 * bsc#1245120 * bsc#1245740 * bsc#1246068 * bsc#1246320 * bsc#1246553 * bsc#1246628 * bsc#1246789 * bsc#1246864 * bsc#1246882 * bsc#1246906 * bsc#1247688 * bsc#1247836 * jsc#MSQA-1023 Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that contains one feature and has 19 fixes can now be installed. ## Description: This update fixes the following issues: uyuni-tools: * Version 5.1.20-0 * Add migration for server monitoring configuration (bsc#1247688) * Version 5.1.19-0 * Add a lowercase version of --logLevel (bsc#1243611) * Stop executing scripts in temporary folder (bsc#1243704) * support config: collect podman inspect for hub container (bsc#1245099) * Use new dedicated path for Cobbler settings (bsc#1244027) * Migrate custom auto installation snippets (bsc#1246320) * Add SUSE Linux Enterprise 15 SP7 to buildin productmap * Fix loading product map from mgradm configuration file (bsc#1246068) * Fix channel override for distro copy * Do not use sudo when running as a root user (bsc#1246882) * Do not require backups to be at the same location for restoring (bsc#1246906) * Fix recomputing proxy images when installing a PTF or TEST (bsc#1246553) * Add mgradm server rename to change the server FQDN (bsc#1229825) * If no DB SSL CA parameter is given, use the other one (bsc#1245120) * More fault tolerant mgradm stop (bsc#1243331) * Backup systemd dropin directory too and create if missing * Add 3rd party SSL options for upgrade and migration scenarios * Do not consider stderr output of podman as an error (bsc#1247836) * Restore SELinux contexts for restored backup volumes (bsc#1244127) * Automatically get up-to-date systemid file on salt based proxy hosts (bsc#1246789) * Bump the default image tag to 5.1.1 * Version 5.1.18-0 * Update translation strings * Version 5.1.17-0 * upgrade saline should use scale function (bsc#1246864) * Version 5.1.16-0 * Use database backup volume as temporary backup location (bsc#1246628) venv-salt-minion: * Improve SL Micro 6.2 detection with grains * Fix functional.states.test_user for SLES 16 and Micro systems * Fix the tests failing on AlmaLinux 10 and other clones * Add `minion_legacy_req_warnings` option to avoid noisy warnings * Use more strict way to fix shebang in the bundle scripts * Remove unused activate script (bsc#1245740) * Filter out zero-length check as the empty files are expected there * Filter out env-script-interpreter for ssh-id-wrapper as not used with the Salt Bundle, but present inside the salt module * venv-salt-minion-rpmlintrc ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-62=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-bash-completion-5.1.20-1.4 * mgrctl-lang-5.1.20-1.4 * mgrctl-zsh-completion-5.1.20-1.4 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-5.1.20-1.4 * mgrctl-5.1.20-1.4 * venv-salt-minion-3006.0-9.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1229825 * https://bugzilla.suse.com/show_bug.cgi?id=1243331 * https://bugzilla.suse.com/show_bug.cgi?id=1243611 * https://bugzilla.suse.com/show_bug.cgi?id=1243704 * https://bugzilla.suse.com/show_bug.cgi?id=1244027 * https://bugzilla.suse.com/show_bug.cgi?id=1244127 * https://bugzilla.suse.com/show_bug.cgi?id=1245099 * https://bugzilla.suse.com/show_bug.cgi?id=1245120 * https://bugzilla.suse.com/show_bug.cgi?id=1245740 * https://bugzilla.suse.com/show_bug.cgi?id=1246068 * https://bugzilla.suse.com/show_bug.cgi?id=1246320 * https://bugzilla.suse.com/show_bug.cgi?id=1246553 * https://bugzilla.suse.com/show_bug.cgi?id=1246628 * https://bugzilla.suse.com/show_bug.cgi?id=1246789 * https://bugzilla.suse.com/show_bug.cgi?id=1246864 * https://bugzilla.suse.com/show_bug.cgi?id=1246882 * https://bugzilla.suse.com/show_bug.cgi?id=1246906 * https://bugzilla.suse.com/show_bug.cgi?id=1247688 * https://bugzilla.suse.com/show_bug.cgi?id=1247836 * https://jira.suse.com/browse/MSQA-1023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:34:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:34:13 -0000 Subject: SUSE-SU-2026:22530-1: important: Security update 5.0.5 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Message-ID: <178368685330.1052.6592836873985785442@5ed4f61072e9> # Security update 5.0.5 for Multi-Linux Manager Client Tools, Salt and Salt Bundle Announcement ID: SUSE-SU-2026:22530-1 Release Date: 2025-07-23T13:31:05Z Rating: important References: * bsc#1236621 * bsc#1236877 * bsc#1238686 * bsc#1238849 * bsc#1238929 * bsc#1240626 * bsc#1240698 * bsc#1242174 * bsc#1243105 * bsc#1243268 * bsc#1243274 * bsc#1243297 * bsc#1243802 * bsc#1244561 * bsc#1244564 * bsc#1244565 * bsc#1244566 * bsc#1244567 * bsc#1244568 * bsc#1244570 * bsc#1244571 * bsc#1244572 * bsc#1244574 * bsc#1244575 * jsc#MSQA-993 Cross-References: * CVE-2024-38822 * CVE-2024-38823 * CVE-2024-38824 * CVE-2024-38825 * CVE-2025-22236 * CVE-2025-22237 * CVE-2025-22238 * CVE-2025-22239 * CVE-2025-22240 * CVE-2025-22241 * CVE-2025-22242 * CVE-2025-22870 * CVE-2025-47287 CVSS scores: * CVE-2024-38822 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-38822 ( SUSE ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2024-38822 ( NVD ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2024-38823 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2024-38823 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-38823 ( NVD ): 2.7 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2024-38824 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2024-38824 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2024-38824 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2024-38824 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-38825 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2024-38825 ( SUSE ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2024-38825 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2025-22236 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L * CVE-2025-22236 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22236 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22237 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-22237 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-22237 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2025-22238 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22238 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2025-22238 ( NVD ): 4.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2025-22239 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L * CVE-2025-22239 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22239 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2025-22240 ( SUSE ): 5.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-22240 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-22240 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2025-22241 ( SUSE ): 5.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22241 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22241 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22242 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22242 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22242 ( NVD ): 5.6 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:H * CVE-2025-22870 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-22870 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-22870 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2025-47287 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47287 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47287 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves 13 vulnerabilities, contains one feature and has 11 fixes can now be installed. ## Description: This update fixes the following issues: golang-github-prometheus-node_exporter: * Security issues fixed: * CVE-2025-22870: Prevent a matching of hosts against proxy patterns to improperly treat an IPv6 zone ID as a hostname component (bsc#1238686) * Other bugs fixed: * Fixed Darwin memory leak * pressure: Fix missing IRQ on older kernels salt, venv-salt-minion: * Security issues fixed: * CVE-2024-38822: Fixed Minion token validation (bsc#1244561) * CVE-2024-38823: Fixed server vulnerability to replay attacks when not using a TLS encrypted transport (bsc#1244564) * CVE-2024-38824: Fixed directory traversal vulnerability in recv_file method (bsc#1244565) * CVE-2024-38825: Fixed salt.auth.pki module authentication issue (bsc#1244566) * CVE-2025-22240: Fixed arbitrary directory creation or file deletion with GitFS (bsc#1244567) * CVE-2025-22236: Fixed Minion event bus authorization bypass (bsc#1244568) * CVE-2025-22241: Fixed the use of un-validated input in the VirtKey class (bsc#1244570) * CVE-2025-22237: Fixed exploitation of the 'on demand' pillar functionality (bsc#1244571) * CVE-2025-22238: Fixed the master's default cache vulnerability to a directory traversal attack (bsc#1244572) * CVE-2025-22239: Fixed the arbitrary event injection on the Salt Master (bsc#1244574) * CVE-2025-22242: Fixed a Denial of Service vulnerability through file read operation (bsc#1244575) * CVE-2025-47287: Fixed a Denial of Service vulnerability in Tornado logging behavior (bsc#1243268) * Other bugs fixed: * Added subsystem filter to udev.exportdb (bsc#1236621) * Added `minion_legacy_req_warnings` option to avoid noisy warnings * Fixed Ubuntu 24.04 edge-case test failures * Fixed refresh of osrelease and related grains on Python 3.10+ * Fixed issue requiring proper Python flavor for dependencies * Require M2Crypto version 0.44.0 or higher * venv-salt-minion: Fixed bundle path in pyvenv.cfg uyuni-tools: * Version 0.1.31-0: * Added the info message about End User License Agreement * Don't migrate py2*-compat-salt.conf files (bsc#1240626) * Check for restorecon before using it (bsc#1240698) * Adjust the distro path in cobbler files after migration (bsc#1238929) * Added mgradm support ptf podman --pullPolicy flag (bsc#1236877) * Support: don't dump files in bound folders (bsc#1243297) * Cleanup host supportconfig files (bsc#1242174) * During migration, check if backup already exists (bsc#1243105) * Removed SHM size limits from all containers (bsc#1243274) * Don't migrate /etc/apache2/vhosts.d/cobbler.conf * Fixed migration --prepare for autoinstallable distributions (bsc#1243802) * Skip instalation if the server is already set up (bsc#1238849) * Bumped the default image tag to 5.0.5 ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6392=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-bash-completion-0.1.31-1.1 * mgrctl-zsh-completion-0.1.31-1.1 * mgrctl-lang-0.1.31-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * venv-salt-minion-3006.0-8.1 * mgrctl-0.1.31-1.1 * golang-github-prometheus-node_exporter-1.9.1-1.1 * golang-github-prometheus-node_exporter-debuginfo-1.9.1-1.1 * mgrctl-debuginfo-0.1.31-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-38822.html * https://www.suse.com/security/cve/CVE-2024-38823.html * https://www.suse.com/security/cve/CVE-2024-38824.html * https://www.suse.com/security/cve/CVE-2024-38825.html * https://www.suse.com/security/cve/CVE-2025-22236.html * https://www.suse.com/security/cve/CVE-2025-22237.html * https://www.suse.com/security/cve/CVE-2025-22238.html * https://www.suse.com/security/cve/CVE-2025-22239.html * https://www.suse.com/security/cve/CVE-2025-22240.html * https://www.suse.com/security/cve/CVE-2025-22241.html * https://www.suse.com/security/cve/CVE-2025-22242.html * https://www.suse.com/security/cve/CVE-2025-22870.html * https://www.suse.com/security/cve/CVE-2025-47287.html * https://bugzilla.suse.com/show_bug.cgi?id=1236621 * https://bugzilla.suse.com/show_bug.cgi?id=1236877 * https://bugzilla.suse.com/show_bug.cgi?id=1238686 * https://bugzilla.suse.com/show_bug.cgi?id=1238849 * https://bugzilla.suse.com/show_bug.cgi?id=1238929 * https://bugzilla.suse.com/show_bug.cgi?id=1240626 * https://bugzilla.suse.com/show_bug.cgi?id=1240698 * https://bugzilla.suse.com/show_bug.cgi?id=1242174 * https://bugzilla.suse.com/show_bug.cgi?id=1243105 * https://bugzilla.suse.com/show_bug.cgi?id=1243268 * https://bugzilla.suse.com/show_bug.cgi?id=1243274 * https://bugzilla.suse.com/show_bug.cgi?id=1243297 * https://bugzilla.suse.com/show_bug.cgi?id=1243802 * https://bugzilla.suse.com/show_bug.cgi?id=1244561 * https://bugzilla.suse.com/show_bug.cgi?id=1244564 * https://bugzilla.suse.com/show_bug.cgi?id=1244565 * https://bugzilla.suse.com/show_bug.cgi?id=1244566 * https://bugzilla.suse.com/show_bug.cgi?id=1244567 * https://bugzilla.suse.com/show_bug.cgi?id=1244568 * https://bugzilla.suse.com/show_bug.cgi?id=1244570 * https://bugzilla.suse.com/show_bug.cgi?id=1244571 * https://bugzilla.suse.com/show_bug.cgi?id=1244572 * https://bugzilla.suse.com/show_bug.cgi?id=1244574 * https://bugzilla.suse.com/show_bug.cgi?id=1244575 * https://jira.suse.com/browse/MSQA-993 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:35:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:35:01 -0000 Subject: SUSE-SU-2026:22528-1: moderate: Security update for SUSE Manager Client Tools Message-ID: <178368690152.1052.6852758503338593838@5ed4f61072e9> # Security update for SUSE Manager Client Tools Announcement ID: SUSE-SU-2026:22528-1 Release Date: 2025-02-13T08:42:02Z Rating: moderate References: * bsc#1228182 * bsc#1228690 * bsc#1229079 * bsc#1229104 * bsc#1231497 * bsc#1231568 * bsc#1231618 * bsc#1231759 * bsc#1232575 * bsc#1232769 * bsc#1232817 * bsc#1233202 * bsc#1233279 * bsc#1233630 * bsc#1233660 * bsc#1233667 * bsc#1234123 * jsc#MSQA-914 Cross-References: * CVE-2024-22037 CVSS scores: * CVE-2024-22037 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L * CVE-2024-22037 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-22037 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-22037 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves one vulnerability, contains one feature and has 16 fixes can now be installed. ## Description: This update fixes the following issues: salt: * Revert setting SELinux context for minion service (bsc#1233667) * Removed System V init support * Fix the condition of alternatives for Tumbleweed and Leap 16 * Build all python bindings for all flavors * Make minion reconnecting on changing master IP (bsc#1228182) * Handle logger exception when flushing already closed file * Include passlib as a recommended dependency * Make Salt Bundle more tolerant to long running jobs (bsc#1228690) uyuni-tools was updated from version 0.1.23-0 to 0.1.27-0: * Security issues fixed: * CVE-2024-22037: Use podman secret to store the database credentials (bsc#1231497) * Other changes and bugs fixed: * Version 0.1.27-0 * Bump the default image tag to 5.0.3 * IsInstalled function fix * Run systemctl daemon-reload after changing the container image config (bsc#1233279) * Coco-replicas-upgrade * Persist search server indexes (bsc#1231759) * Sync deletes files during migration (bsc#1233660) * Ignore coco and hub images when applying PTF if they are not ailable (bsc#1229079) * Add --registry back to mgrpxy (bsc#1233202) * Only add java.hostname on migrated server if not present * Consider the configuration file to detect the coco or hub api images should be pulled (bsc#1229104) * Only raise an error if cloudguestregistryauth fails for PAYG (bsc#1233630) * Add registry.suse.com login to mgradm upgrade podman list (bsc#1234123) * Version 0.1.26-0 * Ignore all zypper caches during migration (bsc#1232769) * Use the uyuni network for all podman containers (bsc#1232817) * Version 0.1.25-0 * Don't migrate enabled systemd services, recreate them (bsc#1232575) * Version 0.1.24-0 * Redact JSESSIONID and pxt-session-cookie values from logs and console output (bsc#1231568) venv-salt-minion: * Included D-Bus python module for SUSE distros (bsc#1231618) * Reverted setting SELinux context for minion service (bsc#1233667) * Make minion reconnecting on changing master IP (bsc#1228182) * Fixed post_start_cleanup.sh shebang to work on all systems * Handle logger exception when flushing already closed file * Made Salt Bundle more tolerant to long running jobs (bsc#1228690) * Modified: * include-rpm * filter-requires.sh ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-6211=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.28-1.1 * venv-salt-minion-3006.0-4.1 * mgrctl-0.1.28-1.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.28-1.1 * mgrctl-bash-completion-0.1.28-1.1 * mgrctl-lang-0.1.28-1.1 ## References: * https://www.suse.com/security/cve/CVE-2024-22037.html * https://bugzilla.suse.com/show_bug.cgi?id=1228182 * https://bugzilla.suse.com/show_bug.cgi?id=1228690 * https://bugzilla.suse.com/show_bug.cgi?id=1229079 * https://bugzilla.suse.com/show_bug.cgi?id=1229104 * https://bugzilla.suse.com/show_bug.cgi?id=1231497 * https://bugzilla.suse.com/show_bug.cgi?id=1231568 * https://bugzilla.suse.com/show_bug.cgi?id=1231618 * https://bugzilla.suse.com/show_bug.cgi?id=1231759 * https://bugzilla.suse.com/show_bug.cgi?id=1232575 * https://bugzilla.suse.com/show_bug.cgi?id=1232769 * https://bugzilla.suse.com/show_bug.cgi?id=1232817 * https://bugzilla.suse.com/show_bug.cgi?id=1233202 * https://bugzilla.suse.com/show_bug.cgi?id=1233279 * https://bugzilla.suse.com/show_bug.cgi?id=1233630 * https://bugzilla.suse.com/show_bug.cgi?id=1233660 * https://bugzilla.suse.com/show_bug.cgi?id=1233667 * https://bugzilla.suse.com/show_bug.cgi?id=1234123 * https://jira.suse.com/browse/MSQA-914 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:35:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:35:36 -0000 Subject: SUSE-SU-2026:22527-1: important: Security update for SUSE Manager Client Tools and Salt Bundle Message-ID: <178368693663.1052.3234911086309547360@5ed4f61072e9> # Security update for SUSE Manager Client Tools and Salt Bundle Announcement ID: SUSE-SU-2026:22527-1 Release Date: 2025-02-03T09:00:46Z Rating: important References: * bsc#1219041 * bsc#1220357 * bsc#1222842 * bsc#1226141 * bsc#1226447 * bsc#1226448 * bsc#1226469 * bsc#1227547 * bsc#1228105 * bsc#1228780 * bsc#1229109 * bsc#1229539 * bsc#1229654 * bsc#1229704 * bsc#1229873 * bsc#1229994 * bsc#1229995 * bsc#1229996 * bsc#1230058 * bsc#1230059 * bsc#1230322 * jsc#MSQA-863 Cross-References: * CVE-2024-0397 * CVE-2024-3651 * CVE-2024-37891 * CVE-2024-4032 * CVE-2024-5569 * CVE-2024-6345 * CVE-2024-6923 * CVE-2024-7592 * CVE-2024-8088 CVSS scores: * CVE-2024-0397 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2024-0397 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2024-3651 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3651 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-3651 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-37891 ( SUSE ): 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2024-37891 ( NVD ): 4.4 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2024-37891 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2024-4032 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-4032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2024-5569 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2024-5569 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-6345 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-6345 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-6923 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2024-6923 ( NVD ): 5.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2024-7592 ( SUSE ): 2.6 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:L * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-7592 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-8088 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-8088 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2024-8088 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:U/V:X/RE:L/U:X Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 An update that solves nine vulnerabilities, contains one feature and has 12 fixes can now be installed. ## Description: This update for SUSE Manager Client Tools and Salt Bundle the following issues: uyuni-tools: venv-salt-minion: * Security fixes on Python 3.11 interpreter: * CVE-2024-7592: Fixed quadratic complexity in parsing -quoted cookie values with backslashes (bsc#1229873, bsc#1230059) * CVE-2024-8088: Prevent malformed payload to cause infinite loops in zipfile.Path (bsc#1229704, bsc#1230058) * CVE-2024-6923: Prevent email header injection due to unquoted newlines (bsc#1228780) * CVE-2024-4032: Rearranging definition of private global IP addresses (bsc#1226448) * CVE-2024-0397: ssl.SSLContext.cert_store_stats() and ssl.SSLContext.get_ca_certs() now correctly lock access to the certificate store, when the ssl.SSLContext is shared across multiple threads (bsc#1226447) * Security fixes on Python dependencies: * CVE-2024-5569: zipp: Fixed a Denial of Service (DoS) vulnerability in the jaraco/zipp library (bsc#1227547, bsc#1229996) * CVE-2024-6345: setuptools: Sanitize any VCS URL used for download (bsc#1228105, bsc#1229995) * CVE-2024-3651: idna: Fix a potential DoS via resource consumption via specially crafted inputs to idna.encode() (bsc#1222842, bsc#1229994) * CVE-2024-37891: urllib3: Added the `Proxy-Authorization` header to the list of headers to strip from requests when redirecting to a different host (bsc#1226469, bsc#1229654) * Other bugs fixed: * Fixed failing x509 tests with OpenSSL < 1.1 * Avoid explicit reading of /etc/salt/minion (bsc#1220357) * Allow NamedLoaderContexts to be returned from loader * Reverted the change making reactor less blocking (bsc#1230322) * Use --cachedir for extension_modules in salt-call (bsc#1226141) * Prevent using SyncWrapper with no reason * Enable post_start_cleanup.sh to work in a transaction * Fixed the SELinux context for Salt Minion service (bsc#1219041) * Increase warn_until_date date for code we still support * Avoid crash on wrong output of systemctl version (bsc#1229539) * Improved error handling with different OpenSSL versions * Fixed cloud Minion configuration for multiple Masters (bsc#1229109) * Use Pygit2 id instead of deprecated oid in gitfs * Added passlib Python module to the bundle ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 zypper in -t patch Multi-Linux-ManagerTools-SL-Micro-669=1 ## Package List: * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (aarch64 ppc64le s390x x86_64) * mgrctl-debuginfo-0.1.23-2.1 * mgrctl-0.1.23-2.1 * venv-salt-minion-3006.0-3.1 * SUSE Multi-Linux Manager Client Tools for SUSE Linux Micro 6 (noarch) * mgrctl-zsh-completion-0.1.23-2.1 * mgrctl-lang-0.1.23-2.1 * mgrctl-bash-completion-0.1.23-2.1 ## References: * https://www.suse.com/security/cve/CVE-2024-0397.html * https://www.suse.com/security/cve/CVE-2024-3651.html * https://www.suse.com/security/cve/CVE-2024-37891.html * https://www.suse.com/security/cve/CVE-2024-4032.html * https://www.suse.com/security/cve/CVE-2024-5569.html * https://www.suse.com/security/cve/CVE-2024-6345.html * https://www.suse.com/security/cve/CVE-2024-6923.html * https://www.suse.com/security/cve/CVE-2024-7592.html * https://www.suse.com/security/cve/CVE-2024-8088.html * https://bugzilla.suse.com/show_bug.cgi?id=1219041 * https://bugzilla.suse.com/show_bug.cgi?id=1220357 * https://bugzilla.suse.com/show_bug.cgi?id=1222842 * https://bugzilla.suse.com/show_bug.cgi?id=1226141 * https://bugzilla.suse.com/show_bug.cgi?id=1226447 * https://bugzilla.suse.com/show_bug.cgi?id=1226448 * https://bugzilla.suse.com/show_bug.cgi?id=1226469 * https://bugzilla.suse.com/show_bug.cgi?id=1227547 * https://bugzilla.suse.com/show_bug.cgi?id=1228105 * https://bugzilla.suse.com/show_bug.cgi?id=1228780 * https://bugzilla.suse.com/show_bug.cgi?id=1229109 * https://bugzilla.suse.com/show_bug.cgi?id=1229539 * https://bugzilla.suse.com/show_bug.cgi?id=1229654 * https://bugzilla.suse.com/show_bug.cgi?id=1229704 * https://bugzilla.suse.com/show_bug.cgi?id=1229873 * https://bugzilla.suse.com/show_bug.cgi?id=1229994 * https://bugzilla.suse.com/show_bug.cgi?id=1229995 * https://bugzilla.suse.com/show_bug.cgi?id=1229996 * https://bugzilla.suse.com/show_bug.cgi?id=1230058 * https://bugzilla.suse.com/show_bug.cgi?id=1230059 * https://bugzilla.suse.com/show_bug.cgi?id=1230322 * https://jira.suse.com/browse/MSQA-863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:36:35 -0000 Subject: SUSE-SU-2026:2838-1: moderate: Security update for libexif Message-ID: <178368699504.1052.4337087172938624183@5ed4f61072e9> # Security update for libexif Announcement ID: SUSE-SU-2026:2838-1 Release Date: 2026-07-10T08:02:27Z Rating: moderate References: * bsc#1259755 * bsc#1262000 * bsc#1262001 Cross-References: * CVE-2026-32775 * CVE-2026-40385 * CVE-2026-40386 CVSS scores: * CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-32775 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for libexif fixes the following issues * CVE-2026-40385: Fixed information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000) * CVE-2026-40386: Fixed denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001) * CVE-2026-32775: Fixed Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2838=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libexif-debugsource-0.6.22-8.16.1 * libexif12-debuginfo-0.6.22-8.16.1 * libexif12-debuginfo-32bit-0.6.22-8.16.1 * libexif-devel-0.6.22-8.16.1 * libexif12-32bit-0.6.22-8.16.1 * libexif12-0.6.22-8.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32775.html * https://www.suse.com/security/cve/CVE-2026-40385.html * https://www.suse.com/security/cve/CVE-2026-40386.html * https://bugzilla.suse.com/show_bug.cgi?id=1259755 * https://bugzilla.suse.com/show_bug.cgi?id=1262000 * https://bugzilla.suse.com/show_bug.cgi?id=1262001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 12:36:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 12:36:44 -0000 Subject: SUSE-SU-2026:2837-1: moderate: Security update for libexif Message-ID: <178368700408.1052.5373650565988420436@5ed4f61072e9> # Security update for libexif Announcement ID: SUSE-SU-2026:2837-1 Release Date: 2026-07-10T08:01:50Z Rating: moderate References: * bsc#1259755 * bsc#1262000 * bsc#1262001 Cross-References: * CVE-2026-32775 * CVE-2026-40385 * CVE-2026-40386 CVSS scores: * CVE-2026-32775 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-32775 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-32775 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40385 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40385 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-40386 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-40386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for libexif fixes the following issues * CVE-2026-40385: Fixed information disclosure and crashes via integer overflow in Nikon MakerNote handling (bsc#1262000) * CVE-2026-40386: Fixed denial of service and information disclosure via integer underflow in MakerNote decoding (bsc#1262001) * CVE-2026-32775: Fixed Buffer overwrite via integer underflow in MakerNotes decoding (bsc#1259755) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2837=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2837=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libexif12-0.6.22-150000.5.12.1 * libexif-debugsource-0.6.22-150000.5.12.1 * libexif12-debuginfo-0.6.22-150000.5.12.1 * libexif-devel-0.6.22-150000.5.12.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libexif12-32bit-0.6.22-150000.5.12.1 * libexif12-32bit-debuginfo-0.6.22-150000.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32775.html * https://www.suse.com/security/cve/CVE-2026-40385.html * https://www.suse.com/security/cve/CVE-2026-40386.html * https://bugzilla.suse.com/show_bug.cgi?id=1259755 * https://bugzilla.suse.com/show_bug.cgi?id=1262000 * https://bugzilla.suse.com/show_bug.cgi?id=1262001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:30:07 -0000 Subject: SUSE-SU-2026:2849-1: important: Security update for krb5 Message-ID: <178370100797.1235.11779489546000614501@aaee731399ed> # Security update for krb5 Announcement ID: SUSE-SU-2026:2849-1 Release Date: 2026-07-10T11:39:24Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2849=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2849=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * krb5-debugsource-1.16.3-46.24.1 * krb5-server-debuginfo-1.16.3-46.24.1 * krb5-doc-1.16.3-46.24.1 * krb5-client-1.16.3-46.24.1 * krb5-plugin-preauth-otp-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-1.16.3-46.24.1 * krb5-client-debuginfo-1.16.3-46.24.1 * krb5-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.24.1 * krb5-debuginfo-1.16.3-46.24.1 * krb5-devel-1.16.3-46.24.1 * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-1.16.3-46.24.1 * krb5-server-1.16.3-46.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * krb5-32bit-1.16.3-46.24.1 * krb5-debuginfo-32bit-1.16.3-46.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * krb5-debugsource-1.16.3-46.24.1 * krb5-server-debuginfo-1.16.3-46.24.1 * krb5-doc-1.16.3-46.24.1 * krb5-client-1.16.3-46.24.1 * krb5-plugin-preauth-otp-1.16.3-46.24.1 * krb5-client-debuginfo-1.16.3-46.24.1 * krb5-debuginfo-32bit-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-1.16.3-46.24.1 * krb5-1.16.3-46.24.1 * krb5-debuginfo-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.16.3-46.24.1 * krb5-devel-1.16.3-46.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.16.3-46.24.1 * krb5-plugin-preauth-otp-debuginfo-1.16.3-46.24.1 * krb5-32bit-1.16.3-46.24.1 * krb5-plugin-preauth-pkinit-1.16.3-46.24.1 * krb5-server-1.16.3-46.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:30:18 -0000 Subject: SUSE-SU-2026:2848-1: important: Security update for krb5, krb5-mini Message-ID: <178370101852.1235.10556840996421868229@aaee731399ed> # Security update for krb5, krb5-mini Announcement ID: SUSE-SU-2026:2848-1 Release Date: 2026-07-10T11:39:12Z Rating: important References: * bsc#1263366 * bsc#1263367 * bsc#1268131 Cross-References: * CVE-2026-11850 * CVE-2026-40355 * CVE-2026-40356 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40355 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40355 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for krb5, krb5-mini fixes the following issues * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). * CVE-2026-40355: Denial of Service via NULL pointer dereference in NegoEx mechanism (bsc#1263366). * CVE-2026-40356: Denial of Service via integer underflow and out-of-bounds read (bsc#1263367). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2848=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-2848=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2848=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2848=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2848=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * krb5-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * Basesystem Module 15-SP7 (x86_64) * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * krb5-1.20.1-150600.11.19.1 * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-mini-devel-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-client-debuginfo-1.20.1-150600.11.19.1 * krb5-devel-1.20.1-150600.11.19.1 * krb5-mini-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-spake-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-client-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 * krb5-mini-debugsource-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-preauth-spake-debuginfo-1.20.1-150600.11.19.1 * krb5-mini-1.20.1-150600.11.19.1 * krb5-plugin-preauth-pkinit-1.20.1-150600.11.19.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150600.11.19.1 * openSUSE Leap 15.6 (x86_64) * krb5-devel-32bit-1.20.1-150600.11.19.1 * krb5-32bit-1.20.1-150600.11.19.1 * krb5-32bit-debuginfo-1.20.1-150600.11.19.1 * openSUSE Leap 15.6 (aarch64_ilp32) * krb5-64bit-debuginfo-1.20.1-150600.11.19.1 * krb5-64bit-1.20.1-150600.11.19.1 * krb5-devel-64bit-1.20.1-150600.11.19.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * krb5-debugsource-1.20.1-150600.11.19.1 * krb5-server-debuginfo-1.20.1-150600.11.19.1 * krb5-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150600.11.19.1 * krb5-plugin-kdb-ldap-1.20.1-150600.11.19.1 * krb5-server-1.20.1-150600.11.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://www.suse.com/security/cve/CVE-2026-40355.html * https://www.suse.com/security/cve/CVE-2026-40356.html * https://bugzilla.suse.com/show_bug.cgi?id=1263366 * https://bugzilla.suse.com/show_bug.cgi?id=1263367 * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:30:24 -0000 Subject: SUSE-SU-2026:2847-1: important: Security update for krb5 Message-ID: <178370102442.1235.7784860547922389845@aaee731399ed> # Security update for krb5 Announcement ID: SUSE-SU-2026:2847-1 Release Date: 2026-07-10T11:38:37Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2847=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2847=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2847=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2847=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2847=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2847=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * krb5-devel-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-mini-debugsource-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-mini-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-spake-debuginfo-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-mini-debuginfo-1.20.1-150500.3.23.1 * krb5-mini-devel-1.20.1-150500.3.23.1 * krb5-plugin-preauth-spake-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * openSUSE Leap 15.5 (aarch64_ilp32) * krb5-devel-64bit-1.20.1-150500.3.23.1 * krb5-64bit-debuginfo-1.20.1-150500.3.23.1 * krb5-64bit-1.20.1-150500.3.23.1 * openSUSE Leap 15.5 (x86_64) * krb5-devel-32bit-1.20.1-150500.3.23.1 * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * krb5-plugin-kdb-ldap-1.20.1-150500.3.23.1 * krb5-devel-1.20.1-150500.3.23.1 * krb5-client-debuginfo-1.20.1-150500.3.23.1 * krb5-server-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-1.20.1-150500.3.23.1 * krb5-client-1.20.1-150500.3.23.1 * krb5-plugin-kdb-ldap-debuginfo-1.20.1-150500.3.23.1 * krb5-plugin-preauth-otp-debuginfo-1.20.1-150500.3.23.1 * krb5-1.20.1-150500.3.23.1 * krb5-debugsource-1.20.1-150500.3.23.1 * krb5-plugin-preauth-pkinit-debuginfo-1.20.1-150500.3.23.1 * krb5-debuginfo-1.20.1-150500.3.23.1 * krb5-server-1.20.1-150500.3.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * krb5-32bit-debuginfo-1.20.1-150500.3.23.1 * krb5-32bit-1.20.1-150500.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:30:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:30:45 -0000 Subject: SUSE-SU-2026:2845-1: important: Security update for perl-List-SomeUtils-XS Message-ID: <178370104576.1235.14790538974227481245@aaee731399ed> # Security update for perl-List-SomeUtils-XS Announcement ID: SUSE-SU-2026:2845-1 Release Date: 2026-07-10T10:31:06Z Rating: important References: * bsc#1269210 Cross-References: * CVE-2026-12844 CVSS scores: * CVE-2026-12844 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12844 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12844 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-List-SomeUtils-XS fixes the following issue * CVE-2026-12844: heap buffer overflow in the `pairwise` function (bsc#1269210). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2845=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2845=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2845=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2845=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2845=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2845=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2845=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2845=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2845=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2845=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2845=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * perl-List-SomeUtils-XS-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * perl-List-SomeUtils-XS-debugsource-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-debuginfo-0.56-150000.3.3.1 * perl-List-SomeUtils-XS-0.56-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12844.html * https://bugzilla.suse.com/show_bug.cgi?id=1269210 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:31:00 -0000 Subject: SUSE-SU-2026:2844-1: important: Security update for gstreamer-plugins-good Message-ID: <178370106049.1235.6195907371104395778@aaee731399ed> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2844-1 Release Date: 2026-07-10T10:29:20Z Rating: important References: * bsc#1268449 Cross-References: * CVE-2026-53705 CVSS scores: * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issue * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2844=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2844=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2844=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2844=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2844=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (aarch64_ilp32) * gstreamer-plugins-good-extra-64bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-64bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-64bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-64bit-debuginfo-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-good-gtk-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-qtqml-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-qtqml-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-1.20.1-150400.3.17.1 * gstreamer-plugins-good-gtk-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-debuginfo-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (x86_64) * gstreamer-plugins-good-jack-32bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-32bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-32bit-debuginfo-1.20.1-150400.3.17.1 * gstreamer-plugins-good-jack-32bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-32bit-1.20.1-150400.3.17.1 * gstreamer-plugins-good-extra-32bit-debuginfo-1.20.1-150400.3.17.1 * openSUSE Leap 15.4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gstreamer-plugins-good-lang-1.20.1-150400.3.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gstreamer-plugins-good-debugsource-1.20.1-150400.3.17.1 * gstreamer-plugins-good-1.20.1-150400.3.17.1 * gstreamer-plugins-good-debuginfo-1.20.1-150400.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:31:07 -0000 Subject: SUSE-SU-2026:2843-1: important: Security update for gstreamer-plugins-good Message-ID: <178370106789.1235.13481698092909342269@aaee731399ed> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2843-1 Release Date: 2026-07-10T10:28:30Z Rating: important References: * bsc#1268449 Cross-References: * CVE-2026-53705 CVSS scores: * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issue * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2843=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2843=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2843=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2843=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2843=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * Basesystem Module 15-SP7 (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (aarch64_ilp32) * gstreamer-plugins-good-jack-64bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-64bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-64bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-64bit-debuginfo-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-good-gtk-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-gtk-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-1.24.0-150600.3.10.1 * gstreamer-plugins-good-qtqml-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-1.24.0-150600.3.10.1 * gstreamer-plugins-good-qtqml-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (x86_64) * gstreamer-plugins-good-32bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-32bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-extra-32bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-32bit-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-32bit-1.24.0-150600.3.10.1 * gstreamer-plugins-good-jack-32bit-1.24.0-150600.3.10.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gstreamer-plugins-good-lang-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gstreamer-plugins-good-debugsource-1.24.0-150600.3.10.1 * gstreamer-plugins-good-gtk-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-debuginfo-1.24.0-150600.3.10.1 * gstreamer-plugins-good-gtk-1.24.0-150600.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:31:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:31:13 -0000 Subject: SUSE-SU-2026:2842-1: important: Security update for gstreamer-plugins-good Message-ID: <178370107387.1235.17140776967113847006@aaee731399ed> # Security update for gstreamer-plugins-good Announcement ID: SUSE-SU-2026:2842-1 Release Date: 2026-07-10T10:25:06Z Rating: important References: * bsc#1268449 Cross-References: * CVE-2026-53705 CVSS scores: * CVE-2026-53705 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-53705 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gstreamer-plugins-good fixes the following issue * CVE-2026-53705: Heap buffer overflow in WavPack decoder via integer overflow (bsc#1268449). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2842=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2842=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2842=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2842=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2842=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * gstreamer-plugins-good-qtqml-1.22.0-150500.4.13.1 * gstreamer-plugins-good-gtk-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-qtqml-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-gtk-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * openSUSE Leap 15.5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * openSUSE Leap 15.5 (x86_64) * gstreamer-plugins-good-32bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-32bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-32bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-32bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-32bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-32bit-1.22.0-150500.4.13.1 * openSUSE Leap 15.5 (aarch64_ilp32) * gstreamer-plugins-good-jack-64bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-jack-64bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-64bit-debuginfo-1.22.0-150500.4.13.1 * gstreamer-plugins-good-64bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-64bit-1.22.0-150500.4.13.1 * gstreamer-plugins-good-extra-64bit-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gstreamer-plugins-good-debugsource-1.22.0-150500.4.13.1 * gstreamer-plugins-good-1.22.0-150500.4.13.1 * gstreamer-plugins-good-debuginfo-1.22.0-150500.4.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gstreamer-plugins-good-lang-1.22.0-150500.4.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53705.html * https://bugzilla.suse.com/show_bug.cgi?id=1268449 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:32:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:32:00 -0000 Subject: SUSE-SU-2026:2841-1: important: Security update for the Linux Kernel Message-ID: <178370112010.1235.11047713755802393078@aaee731399ed> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2841-1 Release Date: 2026-07-10T09:25:02Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves 28 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: Ignore HCI_ERROR_CANCELLED_BY_HOST on adv set terminated event (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2841=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2841=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2841=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2841=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.176.1 * kernel-rt-debugsource-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.176.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.176.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 16:33:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 16:33:21 -0000 Subject: SUSE-SU-2026:2839-1: important: Security update for the Linux Kernel Message-ID: <178370120134.1235.1546393598711901407@aaee731399ed> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2839-1 Release Date: 2026-07-10T09:09:31Z Rating: important References: * bsc#1255416 * bsc#1264610 * bsc#1265421 * bsc#1266214 * bsc#1266969 * bsc#1267205 * bsc#1267531 * bsc#1267684 * bsc#1269100 * bsc#1269574 * bsc#1270059 Cross-References: * CVE-2025-68324 * CVE-2026-43198 * CVE-2026-45970 * CVE-2026-46090 * CVE-2026-46113 * CVE-2026-46266 * CVE-2026-46331 * CVE-2026-52918 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2025-68324 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43198 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43198 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46113 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46113 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46113 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves 10 vulnerabilities and has one security fix can now be installed. ## Description: The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2025-68324: scsi: imm: Fix use-after-free bug caused by unfinished delayed work (bsc#1255416). * CVE-2026-43198: tcp: fix potential race in tcp_v6_syn_recv_sock() (bsc#1264610). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267205). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46113: KVM: x86: Fix shadow paging use-after-free due to unexpected GFN (bsc#1266969). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-2839=1 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-2839=1 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (nosrc x86_64) * kernel-trace-3.0.101-108.213.1 * kernel-ec2-3.0.101-108.213.1 * kernel-xen-3.0.101-108.213.1 * kernel-default-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * kernel-trace-devel-debuginfo-3.0.101-108.213.1 * kernel-ec2-devel-debuginfo-3.0.101-108.213.1 * kernel-default-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debugsource-3.0.101-108.213.1 * kernel-xen-devel-3.0.101-108.213.1 * kernel-default-debugsource-3.0.101-108.213.1 * kernel-ec2-devel-3.0.101-108.213.1 * kernel-default-debuginfo-3.0.101-108.213.1 * kernel-trace-debuginfo-3.0.101-108.213.1 * kernel-source-3.0.101-108.213.1 * kernel-trace-base-3.0.101-108.213.1 * kernel-ec2-debugsource-3.0.101-108.213.1 * kernel-trace-debugsource-3.0.101-108.213.1 * kernel-xen-base-3.0.101-108.213.1 * kernel-ec2-base-3.0.101-108.213.1 * kernel-ec2-debuginfo-3.0.101-108.213.1 * kernel-default-base-3.0.101-108.213.1 * kernel-default-devel-3.0.101-108.213.1 * kernel-syms-3.0.101-108.213.1 * kernel-trace-devel-3.0.101-108.213.1 * kernel-xen-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debuginfo-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (noarch nosrc) * kernel-docs-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 (nosrc x86_64) * kernel-trace-3.0.101-108.213.1 * kernel-ec2-3.0.101-108.213.1 * kernel-xen-3.0.101-108.213.1 * kernel-default-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * kernel-trace-devel-debuginfo-3.0.101-108.213.1 * kernel-ec2-devel-debuginfo-3.0.101-108.213.1 * kernel-default-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debugsource-3.0.101-108.213.1 * kernel-xen-devel-3.0.101-108.213.1 * kernel-default-debugsource-3.0.101-108.213.1 * kernel-ec2-devel-3.0.101-108.213.1 * kernel-default-debuginfo-3.0.101-108.213.1 * kernel-trace-debuginfo-3.0.101-108.213.1 * kernel-source-3.0.101-108.213.1 * kernel-trace-base-3.0.101-108.213.1 * kernel-ec2-debugsource-3.0.101-108.213.1 * kernel-trace-debugsource-3.0.101-108.213.1 * kernel-xen-base-3.0.101-108.213.1 * kernel-ec2-base-3.0.101-108.213.1 * kernel-ec2-debuginfo-3.0.101-108.213.1 * kernel-default-base-3.0.101-108.213.1 * kernel-default-devel-3.0.101-108.213.1 * kernel-syms-3.0.101-108.213.1 * kernel-trace-devel-3.0.101-108.213.1 * kernel-xen-devel-debuginfo-3.0.101-108.213.1 * kernel-xen-debuginfo-3.0.101-108.213.1 * SUSE Linux Enterprise Server 11 SP4 (noarch nosrc) * kernel-docs-3.0.101-108.213.1 ## References: * https://www.suse.com/security/cve/CVE-2025-68324.html * https://www.suse.com/security/cve/CVE-2026-43198.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46113.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1255416 * https://bugzilla.suse.com/show_bug.cgi?id=1264610 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1266214 * https://bugzilla.suse.com/show_bug.cgi?id=1266969 * https://bugzilla.suse.com/show_bug.cgi?id=1267205 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 20:30:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 20:30:09 -0000 Subject: SUSE-SU-2026:2851-1: important: Security update for dracut Message-ID: <178371540911.1251.7625468156168284103@530c474df1e7> # Security update for dracut Announcement ID: SUSE-SU-2026:2851-1 Release Date: 2026-07-10T13:19:22Z Rating: important References: * bsc#1268322 Cross-References: * CVE-2026-6893 CVSS scores: * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for dracut fixes the following issue * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). Changes for dracut: * Update to version 059+suse.570.g2b84048d7: * fix(network-legacy): sanitize DHCP values in dhclient-script.sh (bsc#1268322, CVE-2026-6893) * fix(network-legacy): add input validation to RFC 3442 route parser ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2851=1 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-2851=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dracut-ima-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debuginfo-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-fips-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debugsource-059+suse.570.g2b84048d7-150700.3.17.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (ppc64le x86_64) * dracut-mkinitrd-deprecated-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debugsource-059+suse.570.g2b84048d7-150700.3.17.1 * dracut-debuginfo-059+suse.570.g2b84048d7-150700.3.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 20:30:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 20:30:19 -0000 Subject: SUSE-SU-2026:2850-1: important: Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Message-ID: <178371541900.1251.17169818395575131919@530c474df1e7> # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:2850-1 Release Date: 2026-07-10T12:48:09Z Rating: important References: * bsc#1265678 * bsc#1265700 Cross-References: * CVE-2026-33814 CVSS scores: * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-random, terraform-provider- susepubliccloud, terraform-provider-tls fixes the following issue * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265678, bsc#1265700). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-2850=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-2850=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-kubernetes-1.13.2-150200.6.9.1 * terraform-provider-susepubliccloud-0.0.1-150100.3.11.1 * terraform-provider-random-3.0.0-150200.6.12.1 * terraform-provider-tls-3.0.0-150200.5.12.1 * terraform-provider-aws-3.11.0-150200.6.15.2 * terraform-provider-google-3.43.0-150200.6.9.2 * terraform-provider-helm-2.9.0-150200.6.20.2 * terraform-provider-azurerm-2.32.0-150200.6.9.2 * terraform-provider-external-2.0.0-150200.6.9.2 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-kubernetes-1.13.2-150200.6.9.1 * terraform-provider-susepubliccloud-0.0.1-150100.3.11.1 * terraform-provider-random-3.0.0-150200.6.12.1 * terraform-provider-tls-3.0.0-150200.5.12.1 * terraform-provider-aws-3.11.0-150200.6.15.2 * terraform-provider-google-3.43.0-150200.6.9.2 * terraform-provider-helm-2.9.0-150200.6.20.2 * terraform-provider-azurerm-2.32.0-150200.6.9.2 * terraform-provider-external-2.0.0-150200.6.9.2 ## References: * https://www.suse.com/security/cve/CVE-2026-33814.html * https://bugzilla.suse.com/show_bug.cgi?id=1265678 * https://bugzilla.suse.com/show_bug.cgi?id=1265700 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 10 20:31:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 10 Jul 2026 20:31:04 -0000 Subject: SUSE-SU-2026:2840-1: important: Security update for the Linux Kernel Message-ID: <178371546463.1251.5258118892576251723@530c474df1e7> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2840-1 Release Date: 2026-07-10T09:24:47Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267381 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268049 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46197 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46330 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46330 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46330 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46330 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves 30 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP5 RT kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46330: Revert "net/smc: Introduce TCP ULP support" (bsc#1268049). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: reject short frames before parsing (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2840=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2840=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * kernel-rt-livepatch-5.14.21-150500.13.151.1 * kernel-rt-optional-5.14.21-150500.13.151.1 * kernel-rt_debug-devel-5.14.21-150500.13.151.1 * kernel-rt-optional-debuginfo-5.14.21-150500.13.151.1 * dlm-kmp-rt-5.14.21-150500.13.151.1 * kselftests-kmp-rt-5.14.21-150500.13.151.1 * kernel-rt_debug-vdso-debuginfo-5.14.21-150500.13.151.1 * kernel-rt_debug-debugsource-5.14.21-150500.13.151.1 * kselftests-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-devel-debuginfo-5.14.21-150500.13.151.1 * reiserfs-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-vdso-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-vdso-5.14.21-150500.13.151.1 * cluster-md-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-devel-5.14.21-150500.13.151.1 * ocfs2-kmp-rt-5.14.21-150500.13.151.1 * kernel-rt_debug-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-debugsource-5.14.21-150500.13.151.1 * kernel-rt_debug-devel-debuginfo-5.14.21-150500.13.151.1 * gfs2-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt_debug-vdso-5.14.21-150500.13.151.1 * cluster-md-kmp-rt-5.14.21-150500.13.151.1 * dlm-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * ocfs2-kmp-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-extra-debuginfo-5.14.21-150500.13.151.1 * kernel-syms-rt-5.14.21-150500.13.151.1 * kernel-rt-extra-5.14.21-150500.13.151.1 * kernel-rt-debuginfo-5.14.21-150500.13.151.1 * gfs2-kmp-rt-5.14.21-150500.13.151.1 * kernel-rt-livepatch-devel-5.14.21-150500.13.151.1 * reiserfs-kmp-rt-5.14.21-150500.13.151.1 * openSUSE Leap 15.5 (nosrc x86_64) * kernel-rt-5.14.21-150500.13.151.1 * kernel-rt_debug-5.14.21-150500.13.151.1 * openSUSE Leap 15.5 (noarch) * kernel-devel-rt-5.14.21-150500.13.151.1 * kernel-source-rt-5.14.21-150500.13.151.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * kernel-rt-debuginfo-5.14.21-150500.13.151.1 * kernel-rt-debugsource-5.14.21-150500.13.151.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * kernel-devel-rt-5.14.21-150500.13.151.1 * kernel-source-rt-5.14.21-150500.13.151.1 * SUSE Linux Enterprise Micro 5.5 (nosrc x86_64) * kernel-rt-5.14.21-150500.13.151.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46330.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268049 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:30:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:30:47 -0000 Subject: SUSE-SU-2026:2864-1: important: Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4) Message-ID: <178393144736.1654.5914572997472941906@aaee731399ed> # Security update for the Linux Kernel (Live Patch 45 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2864-1 Release Date: 2026-07-11T21:22:55Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.179 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2864=1 SUSE-2026-2865=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2865=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2864=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-14-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-14-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_42-debugsource-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-14-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_170-default-debuginfo-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-14-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-14-150400.2.1 * kernel-livepatch-5_14_21-150400_24_170-default-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_42-debugsource-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-14-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:31:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:31:02 -0000 Subject: SUSE-SU-2026:2863-1: important: Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393146207.1654.17381781108083163556@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2863-1 Release Date: 2026-07-11T06:44:07Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.59 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2863=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_16-debugsource-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_59-rt-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_59-rt-debuginfo-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:31:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:31:19 -0000 Subject: SUSE-SU-2026:2862-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393147951.1654.2223074230568755079@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2862-1 Release Date: 2026-07-11T06:44:04Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.54 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2862=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_15-debugsource-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-debuginfo-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:32:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:32:01 -0000 Subject: SUSE-SU-2026:2857-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393152184.1654.8822532591730358809@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2857-1 Release Date: 2026-07-11T04:04:28Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.28 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2857=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_28-rt-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_28-rt-debuginfo-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_8-debugsource-9-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:32:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:32:42 -0000 Subject: SUSE-SU-2026:2858-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393156243.1654.16021152725815401113@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2858-1 Release Date: 2026-07-11T04:04:32Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.34 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2858=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2856=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_34-rt-debuginfo-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_9-debugsource-8-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-8-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_10-debugsource-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-debuginfo-8-150700.2.1 * kernel-livepatch-6_4_0-150700_7_34-rt-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:33:18 -0000 Subject: SUSE-SU-2026:2855-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Message-ID: <178393159846.1654.6161436689968815634@aaee731399ed> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2855-1 Release Date: 2026-07-11T04:33:51Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.51 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2855=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2861=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2859=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2860=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_40-rt-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_40-rt-debuginfo-5-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_12-debugsource-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-debuginfo-3-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_13-debugsource-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-debuginfo-4-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_11-debugsource-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_14-debugsource-3-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-debuginfo-6-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:33:25 -0000 Subject: SUSE-SU-2026:2854-1: moderate: Security update for python-urllib3 Message-ID: <178393160551.1654.6026811911550479452@aaee731399ed> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:2854-1 Release Date: 2026-07-10T17:58:58Z Rating: moderate References: * bsc#1254867 * bsc#1270365 Cross-References: * CVE-2025-66471 CVSS scores: * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python-urllib3 fixes the following issue * Regression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2854=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2854=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2854=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2854=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2854=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2854=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2854=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * openSUSE Leap 15.3 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66471.html * https://bugzilla.suse.com/show_bug.cgi?id=1254867 * https://bugzilla.suse.com/show_bug.cgi?id=1270365 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:33:33 -0000 Subject: SUSE-SU-2026:2853-1: important: Security update for tiff Message-ID: <178393161329.1654.1315797228056053801@aaee731399ed> # Security update for tiff Announcement ID: SUSE-SU-2026:2853-1 Release Date: 2026-07-10T17:54:45Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 * CVE-2026-4775 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues: Update to version 4.7.2. Security issues fixed: * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Other updates and bugfixes: * Version 4.7.2: * Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. * Library changes: * New/improved functionalities:: * Add TIFFGetMaxCompressionRatio() and use it in _TIFFReadEncoded[Tile|Strip)AndAllocBuffer() (issue #781) * Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFReadRGBAImage(): prevent integer overflow and later heap overflow (issue #787) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss-fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg-turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss-fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix heap-buffer-overflow in 8BITABGR decode with stride 3 (issue #824) * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. * Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2853=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2853=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2853=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2853=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2853=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * Basesystem Module 15-SP7 (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * tiff-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libtiff6-4.7.2-150600.3.29.1 * libtiff6-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-4.7.2-150600.3.29.1 * tiff-4.7.2-150600.3.29.1 * tiff-debugsource-4.7.2-150600.3.29.1 * tiff-debuginfo-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (x86_64) * libtiff6-32bit-4.7.2-150600.3.29.1 * libtiff-devel-32bit-4.7.2-150600.3.29.1 * libtiff6-32bit-debuginfo-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libtiff6-64bit-4.7.2-150600.3.29.1 * libtiff6-64bit-debuginfo-4.7.2-150600.3.29.1 * libtiff-devel-64bit-4.7.2-150600.3.29.1 * openSUSE Leap 15.6 (noarch) * tiff-docs-4.7.2-150600.3.29.1 * libtiff-devel-docs-4.7.2-150600.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 08:33:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 08:33:39 -0000 Subject: SUSE-SU-2026:2852-1: important: Security update for MozillaThunderbird Message-ID: <178393161965.1654.13247088548909831812@aaee731399ed> # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2026:2852-1 Release Date: 2026-07-10T17:49:29Z Rating: important References: * bsc#1268071 Cross-References: * CVE-2026-12289 * CVE-2026-12290 * CVE-2026-12291 * CVE-2026-12292 * CVE-2026-12294 * CVE-2026-12295 * CVE-2026-12296 * CVE-2026-12297 * CVE-2026-12298 * CVE-2026-12299 * CVE-2026-12302 * CVE-2026-12304 * CVE-2026-12305 * CVE-2026-12306 * CVE-2026-12307 * CVE-2026-12308 * CVE-2026-12309 * CVE-2026-12310 * CVE-2026-12311 * CVE-2026-12312 * CVE-2026-12313 * CVE-2026-12314 * CVE-2026-12315 * CVE-2026-12324 * CVE-2026-12325 * CVE-2026-12327 * CVE-2026-12328 * CVE-2026-12329 * CVE-2026-12330 CVSS scores: * CVE-2026-12289 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12289 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12290 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12290 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12291 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-12292 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12292 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12294 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12294 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12295 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12296 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-12297 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12298 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12298 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12302 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12302 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12304 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12304 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12305 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12305 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12306 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12306 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12307 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12308 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-12309 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12309 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12310 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12310 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12311 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12311 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12312 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12313 ( SUSE ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12313 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-12314 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12314 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-12315 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12315 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12324 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12324 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-12325 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12325 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-12327 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12327 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12328 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12329 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-12329 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12330 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-12330 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 29 vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues Update to Firefox 140.12.0 ESR (MFSA 2026-58, bsc#1268071): * CVE-2026-12289: Privilege escalation in the Graphics: WebRender component. * CVE-2026-12290: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12291: Use-after-free in the Networking: HTTP component. * CVE-2026-12292: Incorrect boundary conditions in the Web Audio component. * CVE-2026-12294: Sandbox escape in the DOM: Workers component. * CVE-2026-12295: Sandbox escape in the DOM: Navigation component. * CVE-2026-12296: Sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12297: Sandbox escape due to incorrect boundary conditions in the Networking component. * CVE-2026-12298: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12299: JIT miscompilation in the DOM: Core & HTML component. * CVE-2026-12302: Mitigation bypass in the DOM: Security component. * CVE-2026-12304: Same-origin policy bypass in the Networking: Cookies component. * CVE-2026-12305: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12306: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12307: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12308: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12309: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12310: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12311: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12312: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12313: Information disclosure, sandbox escape in the Security: Process Sandboxing component. * CVE-2026-12314: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12315: Mitigation bypass in the DOM: Security component. * CVE-2026-12324: Incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-12325: Denial-of-service in the Graphics: ImageLib component. * CVE-2026-12327: Memory safety bugs fixed in Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12328: Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152. * CVE-2026-12329: Memory safety bug fixed in Firefox ESR 140.12. * CVE-2026-12330: Incorrect boundary conditions in the Internationalization component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2852=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-2852=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * MozillaThunderbird-translations-common-140.12.0-150200.8.277.1 * MozillaThunderbird-140.12.0-150200.8.277.1 * MozillaThunderbird-translations-other-140.12.0-150200.8.277.1 * MozillaThunderbird-debuginfo-140.12.0-150200.8.277.1 * MozillaThunderbird-debugsource-140.12.0-150200.8.277.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * MozillaThunderbird-translations-common-140.12.0-150200.8.277.1 * MozillaThunderbird-140.12.0-150200.8.277.1 * MozillaThunderbird-translations-other-140.12.0-150200.8.277.1 * MozillaThunderbird-debuginfo-140.12.0-150200.8.277.1 * MozillaThunderbird-debugsource-140.12.0-150200.8.277.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12289.html * https://www.suse.com/security/cve/CVE-2026-12290.html * https://www.suse.com/security/cve/CVE-2026-12291.html * https://www.suse.com/security/cve/CVE-2026-12292.html * https://www.suse.com/security/cve/CVE-2026-12294.html * https://www.suse.com/security/cve/CVE-2026-12295.html * https://www.suse.com/security/cve/CVE-2026-12296.html * https://www.suse.com/security/cve/CVE-2026-12297.html * https://www.suse.com/security/cve/CVE-2026-12298.html * https://www.suse.com/security/cve/CVE-2026-12299.html * https://www.suse.com/security/cve/CVE-2026-12302.html * https://www.suse.com/security/cve/CVE-2026-12304.html * https://www.suse.com/security/cve/CVE-2026-12305.html * https://www.suse.com/security/cve/CVE-2026-12306.html * https://www.suse.com/security/cve/CVE-2026-12307.html * https://www.suse.com/security/cve/CVE-2026-12308.html * https://www.suse.com/security/cve/CVE-2026-12309.html * https://www.suse.com/security/cve/CVE-2026-12310.html * https://www.suse.com/security/cve/CVE-2026-12311.html * https://www.suse.com/security/cve/CVE-2026-12312.html * https://www.suse.com/security/cve/CVE-2026-12313.html * https://www.suse.com/security/cve/CVE-2026-12314.html * https://www.suse.com/security/cve/CVE-2026-12315.html * https://www.suse.com/security/cve/CVE-2026-12324.html * https://www.suse.com/security/cve/CVE-2026-12325.html * https://www.suse.com/security/cve/CVE-2026-12327.html * https://www.suse.com/security/cve/CVE-2026-12328.html * https://www.suse.com/security/cve/CVE-2026-12329.html * https://www.suse.com/security/cve/CVE-2026-12330.html * https://bugzilla.suse.com/show_bug.cgi?id=1268071 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 12:30:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 12:30:49 -0000 Subject: SUSE-SU-2026:2868-1: important: Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5) Message-ID: <178394584985.1684.5470568238971464463@57e59d802799> # Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2868-1 Release Date: 2026-07-13T08:09:15Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.127 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2869=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-2870=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-2868=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2870=1 SUSE-2026-2868=1 SUSE-2026-2869=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_32-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_29-debugsource-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-15-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_32-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_116-default-debuginfo-18-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-15-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-15-150500.2.2 * kernel-livepatch-5_14_21-150500_55_127-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_121-default-15-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x) * kernel-livepatch-SLE15-SP5_Update_29-debugsource-18-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 12:31:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 12:31:26 -0000 Subject: SUSE-SU-2026:2867-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4) Message-ID: <178394588601.1684.417205355720217611@57e59d802799> # Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2867-1 Release Date: 2026-07-13T08:05:06Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.167 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2867=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2867=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_167-default-21-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_41-debugsource-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-21-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_167-default-21-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_41-debugsource-21-150400.2.1 * kernel-livepatch-5_14_21-150400_24_167-default-debuginfo-21-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 12:32:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 12:32:04 -0000 Subject: SUSE-SU-2026:2866-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise 15 SP6) Message-ID: <178394592479.1684.13190819808812074060@57e59d802799> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2866-1 Release Date: 2026-07-12T23:25:50Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.95 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2866=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2866=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_95-default-6-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_95-default-6-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:30:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:30:38 -0000 Subject: SUSE-SU-2026:22554-1: important: Security update for rust-keylime Message-ID: <178396023892.1820.4669844592337686504@530c474df1e7> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:22554-1 Release Date: 2026-07-09T09:04:26Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for rust-keylime fixes the following issues: Update to version 0.2.9+49. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270614). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270699). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270842). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270999). Other updates and bugfixes: * Update openssl to 0.10.81. * Make tss-esai-sys depend on bindgen 72.1 to support llvm > 21. * Build with Clang <= 21 (bsc#1260596). * Version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 * Version 0.2.9+21: * tests: use Express-style named params in Mockoon endpoints * build(deps): bump pest_derive from 2.8.1 to 2.8.6 * build(deps): bump trybuild from 1.0.110 to 1.0.115 * build(deps): bump log from 0.4.28 to 0.4.29 * build(deps): bump uuid from 1.19.0 to 1.20.0 * build(deps): bump codecov/codecov-action from 5 to 6 * build(deps): bump tracing-subscriber from 0.3.20 to 0.3.23 * build(deps): bump cfg-if from 1.0.3 to 1.0.4 * build(deps): bump tokio from 1.49.0 to 1.50.0 * build(deps): bump actix-web from 4.12.1 to 4.13.0 * build(deps): bump anyhow from 1.0.99 to 1.0.102 * build(deps): bump clap from 4.5.57 to 4.5.60 * build(deps): bump tracing from 0.1.36 to 0.1.44 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1190=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * rust-keylime-0.2.9+49-160000.1.1 * rust-keylime-debugsource-0.2.9+49-160000.1.1 * rust-keylime-debuginfo-0.2.9+49-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:30:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:30:56 -0000 Subject: SUSE-SU-2026:22553-1: important: Security update for curl Message-ID: <178396025618.1820.18277988530639435011@530c474df1e7> # Security update for curl Announcement ID: SUSE-SU-2026:22553-1 Release Date: 2026-07-08T13:45:27Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1187=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-160000.8.1 * curl-debuginfo-8.14.1-160000.8.1 * curl-debugsource-8.14.1-160000.8.1 * curl-8.14.1-160000.8.1 * libcurl4-debuginfo-8.14.1-160000.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:31:18 -0000 Subject: SUSE-SU-2026:22550-1: important: Security update for qemu Message-ID: <178396027886.1820.1867864363506125706@530c474df1e7> # Security update for qemu Announcement ID: SUSE-SU-2026:22550-1 Release Date: 2026-07-07T17:46:01Z Rating: important References: * bsc#1199023 * bsc#1268061 * bsc#1268279 * bsc#1268794 * bsc#1270133 * jsc#PED-9266 Cross-References: * CVE-2026-3886 * CVE-2026-48004 * CVE-2026-48914 CVSS scores: * CVE-2026-3886 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48914 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2026-48914 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities, contains one feature and has two fixes can now be installed. ## Description: This update for qemu fixes the following issues: Update to version 10.0.11. Security issues fixed: * CVE-2026-3886: integer overflow leading to privilege escalation due to lack of proper validation of user-supplied data in the virtio-gpu driver (bsc#1268061). * CVE-2026-48914: heap buffer overflow due to improper size validation in virtio-blk SCSI request handling (bsc#1268794). * CVE-2026-48004: heap use-after-free race condition due to missing rename lock in v9fs_co_readdir_many (bsc#1270133). Other updates and bugfixes: * Version 10.0.11: * Full backport list here: https://lore.kernel.org/qemu- devel/20260627082646.D825717AB67 at think4mjt.localdomain/ * Version 10.0.10: * Full backport list here: https://lore.kernel.org/qemu- devel/20260528061820.CEE521691A9 at think4mjt.localdomain/ * ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * update Linux headers to v6.16-rc3 (jsc#PED-9266). * i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266). * i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266). * [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1174=1 ## Package List: * SUSE Linux Micro 6.2 (noarch) * qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-lang-10.0.11-160000.1.1 * qemu-ipxe-10.0.11-160000.1.1 * qemu-SLOF-10.0.11-160000.1.1 * qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * qemu-10.0.11-160000.1.1 * qemu-chardev-spice-10.0.11-160000.1.1 * qemu-ui-spice-core-10.0.11-160000.1.1 * qemu-hw-usb-host-10.0.11-160000.1.1 * qemu-chardev-spice-debuginfo-10.0.11-160000.1.1 * qemu-ui-opengl-debuginfo-10.0.11-160000.1.1 * qemu-audio-spice-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-10.0.11-160000.1.1 * qemu-guest-agent-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-10.0.11-160000.1.1 * qemu-ui-opengl-10.0.11-160000.1.1 * qemu-debugsource-10.0.11-160000.1.1 * qemu-block-iscsi-10.0.11-160000.1.1 * qemu-img-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-host-debuginfo-10.0.11-160000.1.1 * qemu-img-debuginfo-10.0.11-160000.1.1 * qemu-block-iscsi-debuginfo-10.0.11-160000.1.1 * qemu-audio-spice-10.0.11-160000.1.1 * qemu-hw-usb-redirect-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-redirect-10.0.11-160000.1.1 * qemu-pr-helper-10.0.11-160000.1.1 * qemu-pr-helper-debuginfo-10.0.11-160000.1.1 * qemu-ui-spice-core-debuginfo-10.0.11-160000.1.1 * qemu-ksm-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-10.0.11-160000.1.1 * qemu-debuginfo-10.0.11-160000.1.1 * qemu-guest-agent-10.0.11-160000.1.1 * qemu-hw-display-qxl-debuginfo-10.0.11-160000.1.1 * qemu-tools-10.0.11-160000.1.1 * qemu-hw-display-qxl-10.0.11-160000.1.1 * qemu-tools-debuginfo-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (x86_64) * qemu-vmsr-helper-debuginfo-10.0.11-160000.1.1 * qemu-vmsr-helper-10.0.11-160000.1.1 * qemu-x86-10.0.11-160000.1.1 * qemu-x86-debuginfo-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (s390x) * qemu-s390x-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1 * qemu-s390x-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (ppc64le) * qemu-ppc-10.0.11-160000.1.1 * qemu-ppc-debuginfo-10.0.11-160000.1.1 * SUSE Linux Micro 6.2 (aarch64) * qemu-arm-10.0.11-160000.1.1 * qemu-arm-debuginfo-10.0.11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3886.html * https://www.suse.com/security/cve/CVE-2026-48004.html * https://www.suse.com/security/cve/CVE-2026-48914.html * https://bugzilla.suse.com/show_bug.cgi?id=1199023 * https://bugzilla.suse.com/show_bug.cgi?id=1268061 * https://bugzilla.suse.com/show_bug.cgi?id=1268279 * https://bugzilla.suse.com/show_bug.cgi?id=1268794 * https://bugzilla.suse.com/show_bug.cgi?id=1270133 * https://jira.suse.com/browse/PED-9266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:31:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:31:45 -0000 Subject: SUSE-SU-2026:22546-1: important: Security update for docker-compose Message-ID: <178396030553.1820.90627623211758941@530c474df1e7> # Security update for docker-compose Announcement ID: SUSE-SU-2026:22546-1 Release Date: 2026-07-07T12:34:17Z Rating: important References: * bsc#1239340 * bsc#1239766 * bsc#1265782 * bsc#1266625 Cross-References: * CVE-2025-0495 * CVE-2025-22869 * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker-compose fixes the following issues * CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239766). * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239340). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1168=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * docker-compose-2.33.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1239340 * https://bugzilla.suse.com/show_bug.cgi?id=1239766 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:32:05 -0000 Subject: SUSE-SU-2026:22545-1: important: Security update for jq Message-ID: <178396032503.1820.13481019790565854671@530c474df1e7> # Security update for jq Announcement ID: SUSE-SU-2026:22545-1 Release Date: 2026-07-07T12:32:37Z Rating: important References: * bsc#1244116 * bsc#1262043 * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 * bsc#1265060 * bsc#1265061 * bsc#1265062 * bsc#1265070 Cross-References: * CVE-2025-48060 * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-33948 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 * CVE-2026-40612 * CVE-2026-41256 * CVE-2026-41257 * CVE-2026-43894 CVSS scores: * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40612 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-40612 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41257 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41257 ( NVD ): 6.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43894 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2025-48060: improper handling of string data in `jv_string_empty` can lead to heap buffer overflow and a crash when processing crafted input (bsc#1244116). * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). * CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). * CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). * CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). * CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1169=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libjq1-1.7.1-160000.3.1 * jq-debugsource-1.7.1-160000.3.1 * jq-1.7.1-160000.3.1 * jq-debuginfo-1.7.1-160000.3.1 * libjq1-debuginfo-1.7.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48060.html * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://www.suse.com/security/cve/CVE-2026-40612.html * https://www.suse.com/security/cve/CVE-2026-41256.html * https://www.suse.com/security/cve/CVE-2026-41257.html * https://www.suse.com/security/cve/CVE-2026-43894.html * https://bugzilla.suse.com/show_bug.cgi?id=1244116 * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 * https://bugzilla.suse.com/show_bug.cgi?id=1265060 * https://bugzilla.suse.com/show_bug.cgi?id=1265061 * https://bugzilla.suse.com/show_bug.cgi?id=1265062 * https://bugzilla.suse.com/show_bug.cgi?id=1265070 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:32:11 -0000 Subject: SUSE-SU-2026:22544-1: important: Security update for haproxy Message-ID: <178396033171.1820.1115500895870566626@530c474df1e7> # Security update for haproxy Announcement ID: SUSE-SU-2026:22544-1 Release Date: 2026-07-07T10:11:29Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * Update to version 3.2.21+git0.dbe43be37 * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1166=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * haproxy-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debuginfo-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debugsource-3.2.21+git0.dbe43be37-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:32:20 -0000 Subject: SUSE-SU-2026:22542-1: moderate: Security update for dhcpcd Message-ID: <178396034069.1820.18319890666660269209@530c474df1e7> # Security update for dhcpcd Announcement ID: SUSE-SU-2026:22542-1 Release Date: 2026-07-06T20:10:31Z Rating: moderate References: * bsc#1268761 Cross-References: * CVE-2025-70102 CVSS scores: * CVE-2025-70102 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-70102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-70102 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for dhcpcd fixes the following issue Update to 10.3.2: * CVE-2025-70102: NULL pointer dereference in `parse_option()` when processing a specially crafted configuration input (bsc#1268761). Changes for dhcpcd: * options: Ensure ldop is not NULL dereferenced * DHCP: Don't run double EXPIRE hooks on carrier loss * DHCP: free the state when dropping on state NONE * BSD: don't send uninitialised memory using ps_root_indirectioctl * Fix fallback_time option * IPv4: Ignore DHCP state when building routes * route: Routes may not have an interface assinged * options: Ensure that an overly long bitflag string does not crash * options: Don't assume vsio options have an argument * common: Cast via uintptr_t rather than unsigned long in UNCONST * privsep: Ensure we recv for real after a successful recv MSG_PEEK * DHCP: Add parentheses to macro definitions * ipv6nd: empty IPV6RA_EXPIRE eloop queue when dropping * privsep: enforce message boundaries with MSG_EOR on our messages * Protocols will notify when dhcpcd can exit * DHCP: Don't request T1 and T2 * DHCP: Don't request a lease time * DHCP6: Don't exit if using DHCP4 INFORM in non manager mode * ND: Route Information Option prefix is optional * ipv6: respect slaac hwaddr to really use the hwaddr * When stopping all interfaces at exit and releasing, remove persistance * NetBSD: Delete RTF_CONNECTED route when changing it * privsep: Drain the log when the root process is exiting * eloop: vastly reworked, kqueue and epoll support on by default ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1147=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dhcpcd-debugsource-10.3.2-160000.1.2 * dhcpcd-10.3.2-160000.1.2 * dhcpcd-debuginfo-10.3.2-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-70102.html * https://bugzilla.suse.com/show_bug.cgi?id=1268761 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:32:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:32:50 -0000 Subject: SUSE-SU-2026:22538-1: moderate: Security update for glibc Message-ID: <178396037013.1820.2126670586106958605@530c474df1e7> # Security update for glibc Announcement ID: SUSE-SU-2026:22538-1 Release Date: 2026-07-03T13:25:46Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1157=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * glibc-gconv-modules-extra-2.40-160000.6.1 * glibc-debuginfo-2.40-160000.6.1 * glibc-gconv-modules-extra-debuginfo-2.40-160000.6.1 * glibc-debugsource-2.40-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:33:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:33:10 -0000 Subject: SUSE-SU-2026:22537-1: important: Security update for systemd Message-ID: <178396039031.1820.17996731649321850778@530c474df1e7> # Security update for systemd Announcement ID: SUSE-SU-2026:22537-1 Release Date: 2026-07-03T08:47:49Z Rating: important References: * bsc#1245551 * bsc#1248261 * bsc#1251948 * bsc#1254924 * bsc#1259071 * bsc#1260357 * bsc#1261982 * bsc#1261983 * bsc#1262305 * bsc#1263117 * bsc#1267644 * bsc#1267647 * jsc#PED-15946 * jsc#PED-8812 Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that contains two features and has 12 fixes can now be installed. ## Description: This update for systemd fixes the following issues: Changes in systemd: * Better handle TLS allocation failure (bsc#1254924). * Disable mounting `debugfs` by default (jsc#PED-8812). * Import commit 9e8b5afe0fb2061f4a17a3022469dd62f2683960 (bsc#1267647 bsc#1267644 bsc#1262305 bsc#1263117). * Move `systemd-pcrlock` out from the experimental sub-package to `udev` (bsc#1248261 jsc#PED-15946). * Add a weak runtime dependency on `libtss2-tcti-device0` (bsc#1260357). * Import commit 59336000ef7850eba0963c6a690ff3371c425929 (bsc#1261982 bsc#1261983). * Add a weak runtime dependency on `polkit` (bsc#1259071). * systemd-update-helper: fix the clean-state command only removing `$STATE_DIR/system` instead of `$STATE_DIR/`. * systemd-update-helper: add `--root` option for testing convenience. * systemd-update-helper: fix incorrect skipping of `systemctl disable` during package removal (bsc#1245551). * systemd-update-helper: fix `do_install_units()` incorrectly returning 1 when no units need preset. * systemd.spec: introduce `%bcond_without` docs to allow skipping man pages and `devel-doc`. * systemd.spec: drop the `%{release}` number from the SBAT version (bsc#1251948). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1151=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * systemd-debugsource-257.13-160000.2.1 * systemd-devel-257.13-160000.2.1 * systemd-debuginfo-257.13-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1245551 * https://bugzilla.suse.com/show_bug.cgi?id=1248261 * https://bugzilla.suse.com/show_bug.cgi?id=1251948 * https://bugzilla.suse.com/show_bug.cgi?id=1254924 * https://bugzilla.suse.com/show_bug.cgi?id=1259071 * https://bugzilla.suse.com/show_bug.cgi?id=1260357 * https://bugzilla.suse.com/show_bug.cgi?id=1261982 * https://bugzilla.suse.com/show_bug.cgi?id=1261983 * https://bugzilla.suse.com/show_bug.cgi?id=1262305 * https://bugzilla.suse.com/show_bug.cgi?id=1263117 * https://bugzilla.suse.com/show_bug.cgi?id=1267644 * https://bugzilla.suse.com/show_bug.cgi?id=1267647 * https://jira.suse.com/browse/PED-15946 * https://jira.suse.com/browse/PED-8812 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:33:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:33:49 -0000 Subject: SUSE-SU-2026:2895-1: important: Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 15 SP7) Message-ID: <178396042911.1820.17427081619757866393@530c474df1e7> # Security update for the Linux Kernel (Live Patch 9 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2895-1 Release Date: 2026-07-13T12:11:50Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.31 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2895=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_31-default-8-150700.2.2 * kernel-livepatch-6_4_0-150700_53_31-default-debuginfo-8-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_9-debugsource-8-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:34:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:34:27 -0000 Subject: SUSE-SU-2026:2894-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6) Message-ID: <178396046759.1820.11365189667029857666@530c474df1e7> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2894-1 Release Date: 2026-07-13T12:12:16Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.81 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2894=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2896=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2897=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2894=1 SUSE-2026-2896=1 SUSE-2026-2897=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_53-default-20-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-20-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-20-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_53-default-20-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-9-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_53-default-debuginfo-20-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_12-debugsource-20-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:35:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:35:01 -0000 Subject: SUSE-SU-2026:2889-1: important: Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP4) Message-ID: <178396050167.1820.12331321414079518772@530c474df1e7> # Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2889-1 Release Date: 2026-07-13T10:20:19Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.176 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2889=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2889=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_44-debugsource-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-16-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_44-debugsource-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-16-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-16-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:35:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:35:34 -0000 Subject: SUSE-SU-2026:2888-1: important: Security update for the Linux Kernel (Live Patch 52 for SUSE Linux Enterprise 15 SP4) Message-ID: <178396053435.1820.5310429089614128444@530c474df1e7> # Security update for the Linux Kernel (Live Patch 52 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2888-1 Release Date: 2026-07-13T10:19:55Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.209 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2888=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2888=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-4-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_52-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-4-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_52-debugsource-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-4-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-4-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:36:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:36:12 -0000 Subject: SUSE-SU-2026:2887-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Message-ID: <178396057258.1820.231395166629593623@530c474df1e7> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2887-1 Release Date: 2026-07-13T10:19:34Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.40 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2887=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_12-debugsource-5-150700.2.2 * kernel-livepatch-6_4_0-150700_53_40-default-debuginfo-5-150700.2.2 * kernel-livepatch-6_4_0-150700_53_40-default-5-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:36:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:36:50 -0000 Subject: SUSE-SU-2026:2890-1: important: Security update for the Linux Kernel (Live Patch 34 for SUSE Linux Enterprise 15 SP5) Message-ID: <178396061045.1820.16164415767603207441@530c474df1e7> # Security update for the Linux Kernel (Live Patch 34 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2890-1 Release Date: 2026-07-13T10:20:38Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.133 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2890=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-2872=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-2873=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2872=1 SUSE-2026-2873=1 SUSE-2026-2890=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_31-debugsource-13-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-10-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_31-debugsource-13-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_124-default-13-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_133-default-10-150500.2.2 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-10-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:37:05 -0000 Subject: SUSE-SU-2026:2886-1: moderate: Security update for libslirp Message-ID: <178396062511.1820.1506477260782990314@530c474df1e7> # Security update for libslirp Announcement ID: SUSE-SU-2026:2886-1 Release Date: 2026-07-13T10:09:11Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issues: * CVE-2026-9539: crafted TCP segment with manipulated URG flags and urgent pointers can cause an integer underflow and host-heap memory leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2886=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2886=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2886=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2886=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2886=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libslirp-debugsource-4.7.0+44-150300.18.1 * libslirp-devel-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp0-debuginfo-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libslirp-debugsource-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp0-debuginfo-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libslirp-debugsource-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp0-debuginfo-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libslirp0-debuginfo-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp-debugsource-4.7.0+44-150300.18.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libslirp0-debuginfo-4.7.0+44-150300.18.1 * libslirp0-4.7.0+44-150300.18.1 * libslirp-debugsource-4.7.0+44-150300.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:37:10 -0000 Subject: SUSE-SU-2026:2885-1: moderate: Security update for alsa Message-ID: <178396063070.1820.18353918458618255029@530c474df1e7> # Security update for alsa Announcement ID: SUSE-SU-2026:2885-1 Release Date: 2026-07-13T10:02:46Z Rating: moderate References: * bsc#1268853 Cross-References: * CVE-2026-56109 CVSS scores: * CVE-2026-56109 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56109 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56109 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for alsa fixes the following issue * CVE-2026-56109: crafted ALSA configuration text with nested blocks can cause a double-free and memory corruption (bsc#1268853). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2885=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2885=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2885=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2885=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2885=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libasound2-1.2.6.1-150400.3.3.1 * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libasound2-1.2.6.1-150400.3.3.1 * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * alsa-1.2.6.1-150400.3.3.1 * alsa-devel-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * libasound2-32bit-debuginfo-1.2.6.1-150400.3.3.1 * libatopology2-32bit-debuginfo-1.2.6.1-150400.3.3.1 * alsa-topology-devel-32bit-1.2.6.1-150400.3.3.1 * alsa-devel-32bit-1.2.6.1-150400.3.3.1 * libatopology2-32bit-1.2.6.1-150400.3.3.1 * libasound2-32bit-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le x86_64) * libatopology2-debuginfo-1.2.6.1-150400.3.3.1 * alsa-topology-devel-1.2.6.1-150400.3.3.1 * libatopology2-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libasound2-64bit-1.2.6.1-150400.3.3.1 * libatopology2-64bit-1.2.6.1-150400.3.3.1 * libatopology2-64bit-debuginfo-1.2.6.1-150400.3.3.1 * alsa-devel-64bit-1.2.6.1-150400.3.3.1 * alsa-topology-devel-64bit-1.2.6.1-150400.3.3.1 * libasound2-64bit-debuginfo-1.2.6.1-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * alsa-docs-1.2.6.1-150400.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * alsa-debugsource-1.2.6.1-150400.3.3.1 * libasound2-1.2.6.1-150400.3.3.1 * libasound2-debuginfo-1.2.6.1-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56109.html * https://bugzilla.suse.com/show_bug.cgi?id=1268853 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:37:16 -0000 Subject: SUSE-SU-2026:2883-1: moderate: Security update for nghttp2 Message-ID: <178396063654.1820.8330906072645273224@530c474df1e7> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:2883-1 Release Date: 2026-07-13T09:54:51Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2883=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2883=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2883=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2883=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2883=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libnghttp2-14-1.40.0-150200.25.1 * nghttp2-debuginfo-1.40.0-150200.25.1 * libnghttp2-14-debuginfo-1.40.0-150200.25.1 * nghttp2-debugsource-1.40.0-150200.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:37:22 -0000 Subject: SUSE-SU-2026:2880-1: moderate: Security update for php8 Message-ID: <178396064264.1820.5734281862493167936@530c474df1e7> # Security update for php8 Announcement ID: SUSE-SU-2026:2880-1 Release Date: 2026-07-13T09:39:59Z Rating: moderate References: * bsc#1270351 Cross-References: * CVE-2026-14355 CVSS scores: * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for php8 fixes the following issue * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2880=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php8-bcmath-debuginfo-8.0.30-150400.4.68.1 * php8-zip-debuginfo-8.0.30-150400.4.68.1 * php8-mysql-8.0.30-150400.4.68.1 * php8-pcntl-8.0.30-150400.4.68.1 * php8-bcmath-8.0.30-150400.4.68.1 * php8-embed-debuginfo-8.0.30-150400.4.68.1 * apache2-mod_php8-8.0.30-150400.4.68.1 * php8-openssl-debuginfo-8.0.30-150400.4.68.1 * php8-opcache-debuginfo-8.0.30-150400.4.68.1 * php8-sockets-debuginfo-8.0.30-150400.4.68.1 * php8-fileinfo-8.0.30-150400.4.68.1 * php8-phar-8.0.30-150400.4.68.1 * php8-ctype-debuginfo-8.0.30-150400.4.68.1 * php8-ftp-debuginfo-8.0.30-150400.4.68.1 * php8-fileinfo-debuginfo-8.0.30-150400.4.68.1 * php8-fpm-debuginfo-8.0.30-150400.4.68.1 * php8-bz2-debuginfo-8.0.30-150400.4.68.1 * php8-readline-debuginfo-8.0.30-150400.4.68.1 * php8-tidy-8.0.30-150400.4.68.1 * php8-phar-debuginfo-8.0.30-150400.4.68.1 * php8-calendar-8.0.30-150400.4.68.1 * php8-gettext-debuginfo-8.0.30-150400.4.68.1 * php8-xsl-8.0.30-150400.4.68.1 * php8-fastcgi-debugsource-8.0.30-150400.4.68.1 * php8-gmp-debuginfo-8.0.30-150400.4.68.1 * php8-shmop-debuginfo-8.0.30-150400.4.68.1 * php8-posix-debuginfo-8.0.30-150400.4.68.1 * php8-readline-8.0.30-150400.4.68.1 * php8-bz2-8.0.30-150400.4.68.1 * php8-debuginfo-8.0.30-150400.4.68.1 * php8-sysvmsg-debuginfo-8.0.30-150400.4.68.1 * php8-sysvshm-8.0.30-150400.4.68.1 * php8-zip-8.0.30-150400.4.68.1 * php8-pcntl-debuginfo-8.0.30-150400.4.68.1 * php8-enchant-debuginfo-8.0.30-150400.4.68.1 * php8-opcache-8.0.30-150400.4.68.1 * php8-test-8.0.30-150400.4.68.1 * php8-ldap-8.0.30-150400.4.68.1 * php8-tokenizer-8.0.30-150400.4.68.1 * php8-pdo-debuginfo-8.0.30-150400.4.68.1 * php8-sodium-debuginfo-8.0.30-150400.4.68.1 * php8-curl-debuginfo-8.0.30-150400.4.68.1 * php8-devel-8.0.30-150400.4.68.1 * php8-sqlite-debuginfo-8.0.30-150400.4.68.1 * apache2-mod_php8-debuginfo-8.0.30-150400.4.68.1 * php8-dba-8.0.30-150400.4.68.1 * php8-sockets-8.0.30-150400.4.68.1 * php8-calendar-debuginfo-8.0.30-150400.4.68.1 * php8-sysvsem-8.0.30-150400.4.68.1 * php8-xmlreader-debuginfo-8.0.30-150400.4.68.1 * php8-xmlwriter-debuginfo-8.0.30-150400.4.68.1 * php8-gd-debuginfo-8.0.30-150400.4.68.1 * php8-ftp-8.0.30-150400.4.68.1 * php8-enchant-8.0.30-150400.4.68.1 * php8-odbc-8.0.30-150400.4.68.1 * php8-pgsql-8.0.30-150400.4.68.1 * php8-soap-8.0.30-150400.4.68.1 * php8-dba-debuginfo-8.0.30-150400.4.68.1 * php8-gettext-8.0.30-150400.4.68.1 * php8-ctype-8.0.30-150400.4.68.1 * php8-snmp-8.0.30-150400.4.68.1 * php8-dom-debuginfo-8.0.30-150400.4.68.1 * php8-tidy-debuginfo-8.0.30-150400.4.68.1 * php8-tokenizer-debuginfo-8.0.30-150400.4.68.1 * php8-snmp-debuginfo-8.0.30-150400.4.68.1 * php8-dom-8.0.30-150400.4.68.1 * php8-xmlwriter-8.0.30-150400.4.68.1 * apache2-mod_php8-debugsource-8.0.30-150400.4.68.1 * php8-sysvsem-debuginfo-8.0.30-150400.4.68.1 * php8-xmlreader-8.0.30-150400.4.68.1 * php8-fastcgi-debuginfo-8.0.30-150400.4.68.1 * php8-pgsql-debuginfo-8.0.30-150400.4.68.1 * php8-sysvmsg-8.0.30-150400.4.68.1 * php8-xsl-debuginfo-8.0.30-150400.4.68.1 * php8-openssl-8.0.30-150400.4.68.1 * php8-fastcgi-8.0.30-150400.4.68.1 * php8-shmop-8.0.30-150400.4.68.1 * php8-8.0.30-150400.4.68.1 * php8-fpm-debugsource-8.0.30-150400.4.68.1 * php8-debugsource-8.0.30-150400.4.68.1 * php8-exif-8.0.30-150400.4.68.1 * php8-iconv-debuginfo-8.0.30-150400.4.68.1 * php8-odbc-debuginfo-8.0.30-150400.4.68.1 * php8-sqlite-8.0.30-150400.4.68.1 * php8-zlib-8.0.30-150400.4.68.1 * php8-sysvshm-debuginfo-8.0.30-150400.4.68.1 * php8-fpm-8.0.30-150400.4.68.1 * php8-sodium-8.0.30-150400.4.68.1 * php8-embed-8.0.30-150400.4.68.1 * php8-soap-debuginfo-8.0.30-150400.4.68.1 * php8-embed-debugsource-8.0.30-150400.4.68.1 * php8-exif-debuginfo-8.0.30-150400.4.68.1 * php8-mysql-debuginfo-8.0.30-150400.4.68.1 * php8-intl-debuginfo-8.0.30-150400.4.68.1 * php8-cli-8.0.30-150400.4.68.1 * php8-iconv-8.0.30-150400.4.68.1 * php8-ldap-debuginfo-8.0.30-150400.4.68.1 * php8-curl-8.0.30-150400.4.68.1 * php8-intl-8.0.30-150400.4.68.1 * php8-posix-8.0.30-150400.4.68.1 * php8-gmp-8.0.30-150400.4.68.1 * php8-gd-8.0.30-150400.4.68.1 * php8-mbstring-8.0.30-150400.4.68.1 * php8-zlib-debuginfo-8.0.30-150400.4.68.1 * php8-cli-debuginfo-8.0.30-150400.4.68.1 * php8-pdo-8.0.30-150400.4.68.1 * php8-mbstring-debuginfo-8.0.30-150400.4.68.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:37:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:37:28 -0000 Subject: SUSE-SU-2026:2878-1: important: Security update for libpng15 Message-ID: <178396064846.1820.5623887299931522892@530c474df1e7> # Security update for libpng15 Announcement ID: SUSE-SU-2026:2878-1 Release Date: 2026-07-13T09:27:39Z Rating: important References: * bsc#1258020 Cross-References: * CVE-2026-25646 CVSS scores: * CVE-2026-25646 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-25646 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-25646 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libpng15 fixes the following issue * CVE-2026-25646: heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2878=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2878=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpng15-15-debuginfo-1.5.30-10.16.1 * libpng15-debugsource-1.5.30-10.16.1 * libpng15-15-1.5.30-10.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpng15-15-debuginfo-1.5.30-10.16.1 * libpng15-debugsource-1.5.30-10.16.1 * libpng15-15-1.5.30-10.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25646.html * https://bugzilla.suse.com/show_bug.cgi?id=1258020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:38:30 -0000 Subject: SUSE-SU-2026:2877-1: important: Security update for ImageMagick Message-ID: <178396071028.1820.10612068176191900822@530c474df1e7> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:2877-1 Release Date: 2026-07-13T09:26:30Z Rating: important References: * bsc#1265048 * bsc#1268092 * bsc#1268094 * bsc#1268095 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268103 * bsc#1268105 * bsc#1268107 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268116 * bsc#1268117 * bsc#1268120 * bsc#1268121 * bsc#1268122 * bsc#1268123 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270004 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 * bsc#1271099 Cross-References: * CVE-2026-40169 * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45359 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46557 * CVE-2026-46559 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48724 * CVE-2026-48734 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53461 * CVE-2026-53463 * CVE-2026-53464 * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56374 * CVE-2026-56376 * CVE-2026-56379 CVSS scores: * CVE-2026-40169 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40169 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45359 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45359 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46557 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46559 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46559 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-46559 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48724 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48724 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48724 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48734 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53461 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53464 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53464 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53464 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56374 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 42 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). * CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). * CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). * CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing `ftxt:format` (bsc#1271099). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * CVE-2026-42050: stack buffer overflow via a malicious MIFF file (bsc#1265048). * CVE-2026-42326: out-of-bounds read of single byte via malicious IPTC file (bsc#1268092). * CVE-2026-45031: missing check in the PSD decoder allows bypass of the list- length resource policy when decoding a PSD image (bsc#1268094). * CVE-2026-45358: off-by-one error in the meta encoder can lead to an out-of- bounds read of a single byte (bsc#1268102). * CVE-2026-45359: heap buffer overread via invalid `connected-components` value (bsc#1268095). * CVE-2026-45624: performing a polynomial distortion can lead to an out-of- bounds over-read of 24 bytes (bsc#1268096). * CVE-2026-45664: missing check in the MNG coder can lead to excessive resource use and a DoS (bsc#1268101). * CVE-2026-46520: out-of-bounds write when processing multiple images with different dimensions (bsc#1268112). * CVE-2026-46521: missing check when using LZMA compression in the MIFF encoder can lead to an out-of-bounds write (bsc#1268124). * CVE-2026-46522: missing check in the MIFF decoder can lead to a denial of service via crafted MIFF file (bsc#1268126). * CVE-2026-46523: heap use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46557: missing depth check can lead to a stack buffer overflow in the fx operation when processing a crafted argument (bsc#1268123). * CVE-2026-46559: incorrect check in the JP2 can lead to a heap buffer overwrite of a single byte when specifying certain options (bsc#1268121). * CVE-2026-46692: heap buffer overwrite in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was designed to operate without a challenge-response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer overread in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48724: heap buffer underwrite in the Floyd-Steinberg depth dithering (bsc#1268116). * CVE-2026-48734: missing depth or visited-set check can lead to a stack buffer overflow in the MVG decoder (bsc#1268122). * CVE-2026-48994: missing check of a return value in the MAT decoder can lead to a heap buffer overwrite on 32-bit systems (bsc#1268111). * CVE-2026-49218: missing check in the DCM decoder can lead to a DoS (bsc#1268110). * CVE-2026-53460: missing check for maximum memory request in `AcquireAlignedMemory` can lead to an OOM condition (bsc#1268108). * CVE-2026-53461: incorrect loop in the ICON decoder can lead to an out-of- bounds heap write (bsc#1268107). * CVE-2026-53463: passing incorrect arguments in the distort operation can lead to NULL pointer dereference (bsc#1268105). * CVE-2026-53464: providing invalid options to the wand option parser can lead to a memory leak (bsc#1268103). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-2877=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-2877=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-debugsource-7.1.1.43-150700.3.65.1 * libMagick++-7_Q16HDRI5-7.1.1.43-150700.3.65.1 * libMagickCore-7_Q16HDRI10-7.1.1.43-150700.3.65.1 * libMagickWand-7_Q16HDRI10-7.1.1.43-150700.3.65.1 * libMagick++-devel-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-limited-7.1.1.43-150700.3.65.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-SUSE-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-open-7.1.1.43-150700.3.65.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-devel-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-secure-7.1.1.43-150700.3.65.1 * ImageMagick-7.1.1.43-150700.3.65.1 * ImageMagick-config-7-upstream-websafe-7.1.1.43-150700.3.65.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.1.43-150700.3.65.1 * ImageMagick-debugsource-7.1.1.43-150700.3.65.1 * perl-PerlMagick-debuginfo-7.1.1.43-150700.3.65.1 * perl-PerlMagick-7.1.1.43-150700.3.65.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40169.html * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45359.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46557.html * https://www.suse.com/security/cve/CVE-2026-46559.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48724.html * https://www.suse.com/security/cve/CVE-2026-48734.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53461.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53464.html * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56374.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268095 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268103 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268107 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268116 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268121 * https://bugzilla.suse.com/show_bug.cgi?id=1268122 * https://bugzilla.suse.com/show_bug.cgi?id=1268123 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 * https://bugzilla.suse.com/show_bug.cgi?id=1271099 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:38:40 -0000 Subject: SUSE-SU-2026:2875-1: important: Security update for python-Pillow Message-ID: <178396072048.1820.16732916089906212555@530c474df1e7> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:2875-1 Release Date: 2026-07-13T09:12:44Z Rating: important References: * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 Cross-References: * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 CVSS scores: * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). * CVE-2026-54060: a font can trigger excessive allocation during conversion or saving (bsc#1270410). * CVE-2026-55379: bypass of decompression bomb protection, allowing excessive memory allocation (bsc#1270411). * CVE-2026-55380: crafted .gd file can trigger excessive C-heap allocation when loaded (bsc#1270412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2875=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-2875=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-debuginfo-7.2.0-150300.3.27.1 * python3-Pillow-7.2.0-150300.3.27.1 * python3-Pillow-tk-7.2.0-150300.3.27.1 * python-Pillow-debugsource-7.2.0-150300.3.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 16:38:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 16:38:46 -0000 Subject: SUSE-SU-2026:2874-1: moderate: Security update for sccache Message-ID: <178396072608.1820.4655237468156226873@530c474df1e7> # Security update for sccache Announcement ID: SUSE-SU-2026:2874-1 Release Date: 2026-07-13T09:11:08Z Rating: moderate References: * bsc#1270206 Cross-References: * CVE-2026-41676 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for sccache fixes the following issue * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270206). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2874=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * sccache-0.4.2~4-150400.3.12.1 * sccache-debuginfo-0.4.2~4-150400.3.12.1 * sccache-debugsource-0.4.2~4-150400.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:31:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 20:31:42 -0000 Subject: SUSE-SU-2026:2914-1: important: Security update for the Linux Kernel Message-ID: <178397470250.1786.2695528649078287677@57e59d802799> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:2914-1 Release Date: 2026-07-13T14:56:44Z Rating: important References: * bsc#1255616 * bsc#1259891 * bsc#1261604 * bsc#1262655 * bsc#1262674 * bsc#1263072 * bsc#1263123 * bsc#1263169 * bsc#1263560 * bsc#1263563 * bsc#1263573 * bsc#1263993 * bsc#1263996 * bsc#1264033 * bsc#1264039 * bsc#1264065 * bsc#1264073 * bsc#1264088 * bsc#1264236 * bsc#1264254 * bsc#1264261 * bsc#1264294 * bsc#1264337 * bsc#1264414 * bsc#1264437 * bsc#1264449 * bsc#1264618 * bsc#1264734 * bsc#1264748 * bsc#1265113 * bsc#1265421 * bsc#1265629 * bsc#1266397 * bsc#1266847 * bsc#1266899 * bsc#1266928 * bsc#1266929 * bsc#1266971 * bsc#1267430 * bsc#1267437 * bsc#1267458 * bsc#1267473 * bsc#1267635 * bsc#1267637 * bsc#1267684 * bsc#1267920 * bsc#1267968 * bsc#1267993 * bsc#1268037 * bsc#1269033 * bsc#1269100 * bsc#1269103 * bsc#1269135 * bsc#1269137 * bsc#1269159 * bsc#1269195 * bsc#1269386 * bsc#1269397 * bsc#1269398 * bsc#1269506 * bsc#1269574 * bsc#1269690 * bsc#1269786 * bsc#1269904 * bsc#1270059 Cross-References: * CVE-2023-53995 * CVE-2026-23255 * CVE-2026-23451 * CVE-2026-31462 * CVE-2026-31499 * CVE-2026-31502 * CVE-2026-31580 * CVE-2026-31592 * CVE-2026-31670 * CVE-2026-31677 * CVE-2026-31680 * CVE-2026-31773 * CVE-2026-31781 * CVE-2026-43035 * CVE-2026-43036 * CVE-2026-43043 * CVE-2026-43047 * CVE-2026-43051 * CVE-2026-43080 * CVE-2026-43089 * CVE-2026-43093 * CVE-2026-43112 * CVE-2026-43117 * CVE-2026-43139 * CVE-2026-43233 * CVE-2026-43279 * CVE-2026-43284 * CVE-2026-43336 * CVE-2026-43456 * CVE-2026-43472 * CVE-2026-43492 * CVE-2026-45840 * CVE-2026-45912 * CVE-2026-45948 * CVE-2026-45960 * CVE-2026-46028 * CVE-2026-46065 * CVE-2026-46069 * CVE-2026-46082 * CVE-2026-46124 * CVE-2026-46133 * CVE-2026-46253 * CVE-2026-46254 * CVE-2026-46266 * CVE-2026-46275 * CVE-2026-46299 * CVE-2026-46320 * CVE-2026-46328 * CVE-2026-46331 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52954 * CVE-2026-52955 * CVE-2026-52957 * CVE-2026-52962 * CVE-2026-52972 * CVE-2026-53040 * CVE-2026-53041 * CVE-2026-53075 * CVE-2026-53148 * CVE-2026-53150 * CVE-2026-53194 * CVE-2026-53253 * CVE-2026-53287 * CVE-2026-53359 CVSS scores: * CVE-2023-53995 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2023-53995 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23255 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23255 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23255 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31462 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31462 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31499 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31499 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31592 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31592 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31592 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31670 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31670 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31677 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31677 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31680 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31680 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31773 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31773 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31781 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31781 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43035 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43036 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43043 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43043 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43047 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43051 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43051 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43080 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43080 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43089 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43093 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43112 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43112 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43112 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43112 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43117 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43117 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43117 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43139 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43139 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-43233 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43233 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43279 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43284 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-43284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43336 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-43336 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43336 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-43456 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43472 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43492 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43492 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45840 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L * CVE-2026-45840 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-45840 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45948 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45948 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45960 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45960 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45960 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46028 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46065 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46069 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46069 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46082 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46082 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46124 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46133 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46254 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46275 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46299 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46328 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52954 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52957 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52957 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52962 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52962 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53040 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53040 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53075 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-53075 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53148 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53148 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53148 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53148 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53150 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53150 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53150 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53194 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53194 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53194 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53287 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 65 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2023-53995: net: ipv4: fix one memleak in __inet_del_ifa() (bsc#1255616). * CVE-2026-23255: net: add proper RCU protection to /proc/net/ptype (bsc#1259891). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31462: drm/amdgpu: prevent immediate PASID reuse case (bsc#1262655). * CVE-2026-31499: Bluetooth: L2CAP: Fix deadlock in l2cap_conn_del() (bsc#1262674). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-31592: KVM: SEV: Protect _all_ of sev_mem_enc_register_region() with kvm->lock (bsc#1263123). * CVE-2026-31670: net: rfkill: prevent unlimited numbers of rfkill events from being created (bsc#1263573). * CVE-2026-31677: crypto: af_alg - limit RX SG extraction by receive buffer budget (bsc#1263560). * CVE-2026-31680: net: ipv6: flowlabel: defer exclusive option free until RCU teardown (bsc#1263563). * CVE-2026-31773: Bluetooth: SMP: derive legacy responder STK authentication from MITM state (bsc#1264039). * CVE-2026-31781: drm/ioc32: stop speculation on the drm_compat_ioctl path (bsc#1264033). * CVE-2026-43035: net: sched: cls_api: fix tc_chain_fill_node to initialize tcm_info to zero to prevent an info-leak (bsc#1263996). * CVE-2026-43036: net: use skb_header_pointer() for TCPv4 GSO frag_off check (bsc#1263993). * CVE-2026-43043: crypto: af-alg - fix NULL pointer dereference in scatterwalk (bsc#1264088). * CVE-2026-43047: HID: multitouch: Check to ensure report responses match the request (bsc#1264073). * CVE-2026-43051: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq (bsc#1264065). * CVE-2026-43080: l2tp: Drop large packets with UDP encap (bsc#1264236). * CVE-2026-43089: xfrm_user: fix info leak in build_mapping() (bsc#1264261). * CVE-2026-43093: xsk: tighten UMEM headroom validation to account for tailroom and min frame (bsc#1264254). * CVE-2026-43112: fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath (bsc#1264437). * CVE-2026-43117: btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file() (bsc#1264414). * CVE-2026-43139: xfrm6: fix uninitialized saddr in xfrm6_get_saddr() (bsc#1264294). * CVE-2026-43233: netfilter: nf_conntrack_h323: fix OOB read in decode_choice() (bsc#1264337). * CVE-2026-43279: ALSA: usb-audio: Add sanity check for OOB writes at silencing (bsc#1264618). * CVE-2026-43336: lib/crypto: chacha: Zeroize permuted_state before it leaves scope (bsc#1265113). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43472: unshare: fix unshare_fs() handling (bsc#1264748). * CVE-2026-43492: lib/crypto: mpi: Fix integer underflow in mpi_read_raw_from_sgl() (bsc#1265629). * CVE-2026-45840: openvswitch: cap upcall PID array size and pre-size vport replies (bsc#1266397). * CVE-2026-45912: ext4: don't cache extent during splitting extent (bsc#1266899). * CVE-2026-45948: ext4: fix memory leak in ext4_ext_shift_extents() (bsc#1266929). * CVE-2026-45960: hfsplus: return error when node already exists in hfs_bnode_create (bsc#1266971). * CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests (bsc#1267430). * CVE-2026-46065: fbdev: defio: Disconnect deferred I/O from the lifetime of struct (bsc#1267458). * CVE-2026-46069: wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() (bsc#1267437). * CVE-2026-46082: KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 (bsc#1267473). * CVE-2026-46124: isofs: validate block number from NFS file handle in isofs_export_iget (bsc#1266847). * CVE-2026-46133: RDMA/rxe: Reject unknown opcodes before ICRC processing (bsc#1266928). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46254: AppArmor: Allow apparmor to handle unaligned dfa tables (bsc#1267637). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46275: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths (bsc#1267968). * CVE-2026-46299: hfsplus: fix held lock freed on hfsplus_fill_super() (bsc#1267920). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46328: apparmor: fix rlimit for posix cpu timers (bsc#1268037). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52954: libceph: handle rbtree insertion error in decode_choose_args() (bsc#1269137). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52957: libceph: Fix potential null-ptr-deref in decode_choose_args() (bsc#1269103). * CVE-2026-52962: ceph: fix a buffer leak in __ceph_setxattr() (bsc#1269135). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-53040: ocfs2: validate bg_bits during freefrag scan (bsc#1269397). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53075: ppp: require CAP_NET_ADMIN in target netns for unattached ioctls (bsc#1269690). * CVE-2026-53148: thunderbolt: Clamp XDomain response data copy to allocation size (bsc#1269786). * CVE-2026-53150: thunderbolt: Reject zero-length property entries in validator (bsc#1269386). * CVE-2026-53194: USB: serial: kl5kusb105: fix bulk-out buffer overflow (bsc#1269904). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53287: audit: fix incorrect inheritable capability in CAPSET records (bsc#1269506). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). The following non security issues were fixed: * btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (git-fixes). * libceph: add non-asserting rbtree insertion helper (bsc#1269137). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2914=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2914=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2914=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * kernel-default-devel-debuginfo-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gfs2-kmp-default-debuginfo-4.12.14-122.320.1 * cluster-md-kmp-default-4.12.14-122.320.1 * kernel-syms-4.12.14-122.320.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.320.1 * gfs2-kmp-default-4.12.14-122.320.1 * ocfs2-kmp-default-4.12.14-122.320.1 * dlm-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-debuginfo-4.12.14-122.320.1 * dlm-kmp-default-4.12.14-122.320.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-base-debuginfo-4.12.14-122.320.1 * kernel-default-debugsource-4.12.14-122.320.1 * kernel-default-base-4.12.14-122.320.1 * kernel-default-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * kernel-source-4.12.14-122.320.1 * kernel-macros-4.12.14-122.320.1 * kernel-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x) * kernel-default-man-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cluster-md-kmp-default-4.12.14-122.320.1 * kernel-default-devel-debuginfo-4.12.14-122.320.1 * gfs2-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-syms-4.12.14-122.320.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.320.1 * dlm-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-debuginfo-4.12.14-122.320.1 * gfs2-kmp-default-4.12.14-122.320.1 * ocfs2-kmp-default-4.12.14-122.320.1 * dlm-kmp-default-4.12.14-122.320.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.320.1 * kernel-default-base-debuginfo-4.12.14-122.320.1 * kernel-default-debugsource-4.12.14-122.320.1 * kernel-default-base-4.12.14-122.320.1 * kernel-default-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * kernel-macros-4.12.14-122.320.1 * kernel-source-4.12.14-122.320.1 * kernel-devel-4.12.14-122.320.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (nosrc x86_64) * kernel-default-4.12.14-122.320.1 * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kernel-default-kgraft-4.12.14-122.320.1 * kgraft-patch-4_12_14-122_320-default-1-8.3.1 * kernel-default-kgraft-devel-4.12.14-122.320.1 * kernel-default-debuginfo-4.12.14-122.320.1 * kernel-default-debugsource-4.12.14-122.320.1 * SUSE Linux Enterprise Live Patching 12-SP5 (nosrc) * kernel-default-4.12.14-122.320.1 ## References: * https://www.suse.com/security/cve/CVE-2023-53995.html * https://www.suse.com/security/cve/CVE-2026-23255.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31462.html * https://www.suse.com/security/cve/CVE-2026-31499.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-31580.html * https://www.suse.com/security/cve/CVE-2026-31592.html * https://www.suse.com/security/cve/CVE-2026-31670.html * https://www.suse.com/security/cve/CVE-2026-31677.html * https://www.suse.com/security/cve/CVE-2026-31680.html * https://www.suse.com/security/cve/CVE-2026-31773.html * https://www.suse.com/security/cve/CVE-2026-31781.html * https://www.suse.com/security/cve/CVE-2026-43035.html * https://www.suse.com/security/cve/CVE-2026-43036.html * https://www.suse.com/security/cve/CVE-2026-43043.html * https://www.suse.com/security/cve/CVE-2026-43047.html * https://www.suse.com/security/cve/CVE-2026-43051.html * https://www.suse.com/security/cve/CVE-2026-43080.html * https://www.suse.com/security/cve/CVE-2026-43089.html * https://www.suse.com/security/cve/CVE-2026-43093.html * https://www.suse.com/security/cve/CVE-2026-43112.html * https://www.suse.com/security/cve/CVE-2026-43117.html * https://www.suse.com/security/cve/CVE-2026-43139.html * https://www.suse.com/security/cve/CVE-2026-43233.html * https://www.suse.com/security/cve/CVE-2026-43279.html * https://www.suse.com/security/cve/CVE-2026-43284.html * https://www.suse.com/security/cve/CVE-2026-43336.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43472.html * https://www.suse.com/security/cve/CVE-2026-43492.html * https://www.suse.com/security/cve/CVE-2026-45840.html * https://www.suse.com/security/cve/CVE-2026-45912.html * https://www.suse.com/security/cve/CVE-2026-45948.html * https://www.suse.com/security/cve/CVE-2026-45960.html * https://www.suse.com/security/cve/CVE-2026-46028.html * https://www.suse.com/security/cve/CVE-2026-46065.html * https://www.suse.com/security/cve/CVE-2026-46069.html * https://www.suse.com/security/cve/CVE-2026-46082.html * https://www.suse.com/security/cve/CVE-2026-46124.html * https://www.suse.com/security/cve/CVE-2026-46133.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46254.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46275.html * https://www.suse.com/security/cve/CVE-2026-46299.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46328.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52954.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52957.html * https://www.suse.com/security/cve/CVE-2026-52962.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53040.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53075.html * https://www.suse.com/security/cve/CVE-2026-53148.html * https://www.suse.com/security/cve/CVE-2026-53150.html * https://www.suse.com/security/cve/CVE-2026-53194.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53287.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1255616 * https://bugzilla.suse.com/show_bug.cgi?id=1259891 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1262655 * https://bugzilla.suse.com/show_bug.cgi?id=1262674 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1263123 * https://bugzilla.suse.com/show_bug.cgi?id=1263169 * https://bugzilla.suse.com/show_bug.cgi?id=1263560 * https://bugzilla.suse.com/show_bug.cgi?id=1263563 * https://bugzilla.suse.com/show_bug.cgi?id=1263573 * https://bugzilla.suse.com/show_bug.cgi?id=1263993 * https://bugzilla.suse.com/show_bug.cgi?id=1263996 * https://bugzilla.suse.com/show_bug.cgi?id=1264033 * https://bugzilla.suse.com/show_bug.cgi?id=1264039 * https://bugzilla.suse.com/show_bug.cgi?id=1264065 * https://bugzilla.suse.com/show_bug.cgi?id=1264073 * https://bugzilla.suse.com/show_bug.cgi?id=1264088 * https://bugzilla.suse.com/show_bug.cgi?id=1264236 * https://bugzilla.suse.com/show_bug.cgi?id=1264254 * https://bugzilla.suse.com/show_bug.cgi?id=1264261 * https://bugzilla.suse.com/show_bug.cgi?id=1264294 * https://bugzilla.suse.com/show_bug.cgi?id=1264337 * https://bugzilla.suse.com/show_bug.cgi?id=1264414 * https://bugzilla.suse.com/show_bug.cgi?id=1264437 * https://bugzilla.suse.com/show_bug.cgi?id=1264449 * https://bugzilla.suse.com/show_bug.cgi?id=1264618 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1264748 * https://bugzilla.suse.com/show_bug.cgi?id=1265113 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1265629 * https://bugzilla.suse.com/show_bug.cgi?id=1266397 * https://bugzilla.suse.com/show_bug.cgi?id=1266847 * https://bugzilla.suse.com/show_bug.cgi?id=1266899 * https://bugzilla.suse.com/show_bug.cgi?id=1266928 * https://bugzilla.suse.com/show_bug.cgi?id=1266929 * https://bugzilla.suse.com/show_bug.cgi?id=1266971 * https://bugzilla.suse.com/show_bug.cgi?id=1267430 * https://bugzilla.suse.com/show_bug.cgi?id=1267437 * https://bugzilla.suse.com/show_bug.cgi?id=1267458 * https://bugzilla.suse.com/show_bug.cgi?id=1267473 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267637 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267920 * https://bugzilla.suse.com/show_bug.cgi?id=1267968 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268037 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269103 * https://bugzilla.suse.com/show_bug.cgi?id=1269135 * https://bugzilla.suse.com/show_bug.cgi?id=1269137 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269386 * https://bugzilla.suse.com/show_bug.cgi?id=1269397 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269506 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269690 * https://bugzilla.suse.com/show_bug.cgi?id=1269786 * https://bugzilla.suse.com/show_bug.cgi?id=1269904 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:31:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 20:31:57 -0000 Subject: SUSE-SU-2026:2909-1: important: Security update for the Linux Kernel (Live Patch 72 for SUSE Linux Enterprise 12 SP5) Message-ID: <178397471717.1786.16893752727903724295@57e59d802799> # Security update for the Linux Kernel (Live Patch 72 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2909-1 Release Date: 2026-07-13T14:16:52Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.272 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2909=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_272-default-14-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:32:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 20:32:32 -0000 Subject: SUSE-SU-2026:2910-1: important: Security update for the Linux Kernel (Live Patch 47 for SUSE Linux Enterprise 15 SP4) Message-ID: <178397475224.1786.11195323267167675599@57e59d802799> # Security update for the Linux Kernel (Live Patch 47 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2910-1 Release Date: 2026-07-13T14:17:06Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.187 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2910=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2900=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2910=1 SUSE-2026-2900=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_187-default-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-10-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_187-default-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-10-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-10-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-10-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:33:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 20:33:09 -0000 Subject: SUSE-SU-2026:2899-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP5) Message-ID: <178397478996.1786.2561460930631511824@57e59d802799> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2899-1 Release Date: 2026-07-13T12:33:59Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.110 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2899=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2899=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-21-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-21-150500.2.2 * kernel-livepatch-5_14_21-150500_55_110-default-21-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_110-default-debuginfo-21-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_27-debugsource-21-150500.2.2 * kernel-livepatch-5_14_21-150500_55_110-default-21-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Jul 13 20:33:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 13 Jul 2026 20:33:50 -0000 Subject: SUSE-SU-2026:2902-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Message-ID: <178397483042.1786.17444695776933957450@57e59d802799> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2902-1 Release Date: 2026-07-13T15:45:10Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.28 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2911=1 SUSE-2026-2913=1 SUSE-2026-2912=1 SUSE-2026-2917=1 SUSE-2026-2908=1 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2916=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2915=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2902=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2906=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2904=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2898=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2903=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2905=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2901=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2907=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2908=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2911=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2913=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2912=1 SUSE-SLE-Module-Live-Patching-15-SP6-2026-2917=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_22-rt-10-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_2-debugsource-18-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-14-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_1-debugsource-19-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_5-debugsource-11-150700.2.1 * kernel-livepatch-6_4_0-150700_5-rt-19-150700.3.1 * kernel-livepatch-6_4_0-150700_7_25-rt-debuginfo-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_22-rt-debuginfo-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-debuginfo-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_8-rt-18-150700.2.1 * kernel-livepatch-6_4_0-150700_5-rt-debuginfo-19-150700.3.1 * kernel-livepatch-SLE15-SP7-RT_Update_3-debugsource-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-debuginfo-14-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_0-debugsource-19-150700.3.1 * kernel-livepatch-SLE15-SP7-RT_Update_4-debugsource-14-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_6-debugsource-10-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-debuginfo-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_8-rt-debuginfo-18-150700.2.1 * kernel-livepatch-6_4_0-150700_7_25-rt-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_7-debugsource-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_3-rt-debuginfo-19-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_3-rt-19-150700.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_28-default-debuginfo-9-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_8-debugsource-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_25-default-9-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_7-debugsource-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_25-default-debuginfo-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_28-default-9-150700.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_17-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-11-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_16-debugsource-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-18-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-18-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-18-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_17-debugsource-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-11-150600.2.2 * kernel-livepatch-6_4_0-150600_23_73-default-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_16-debugsource-11-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-14-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-9-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_13-debugsource-18-150600.2.2 * kernel-livepatch-6_4_0-150600_23_65-default-14-150600.2.2 * kernel-livepatch-6_4_0-150600_23_78-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-debuginfo-18-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_84-default-9-150600.2.2 * kernel-livepatch-6_4_0-150600_23_60-default-18-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:30:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:30:49 -0000 Subject: SUSE-SU-2026:2933-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP5) Message-ID: <178401784966.27.336291723168721535@178315a69387> # Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2933-1 Release Date: 2026-07-13T19:10:43Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 23 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.113 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2933=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2933=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_113-default-20-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-20-150500.2.2 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-20-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_113-default-20-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_28-debugsource-20-150500.2.2 * kernel-livepatch-5_14_21-150500_55_113-default-debuginfo-20-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:31:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:31:27 -0000 Subject: SUSE-SU-2026:2932-1: important: Security update for the Linux Kernel (Live Patch 50 for SUSE Linux Enterprise 15 SP4) Message-ID: <178401788727.27.9011423254799494814@178315a69387> # Security update for the Linux Kernel (Live Patch 50 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2932-1 Release Date: 2026-07-13T20:00:29Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.200 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2934=1 SUSE-2026-2935=1 SUSE-2026-2932=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2934=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2935=1 SUSE-SLE-Module-Live- Patching-15-SP4-2026-2932=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-8-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-6-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-8-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-6-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:32:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:32:11 -0000 Subject: SUSE-SU-2026:2920-1: important: Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP4) Message-ID: <178401793130.27.16825873162701478084@178315a69387> # Security update for the Linux Kernel (Live Patch 43 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2920-1 Release Date: 2026-07-13T16:50:39Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.173 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2920=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2920=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-17-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-17-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_43-debugsource-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-17-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:32:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:32:56 -0000 Subject: SUSE-SU-2026:2930-1: important: Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 15 SP7) Message-ID: <178401797638.27.11832492833424045081@178315a69387> # Security update for the Linux Kernel (Live Patch 5 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2930-1 Release Date: 2026-07-13T18:35:20Z Rating: important References: * bsc#1256615 * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2025-71089 * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2025-71089 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-71089 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.19 fixes various security issues The following security issues were fixed: * CVE-2025-71089: iommu: disable SVA when CONFIG_X86 is set (bsc#1256615). * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2927=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2928=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2919=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2918=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2930=1 SUSE-SLE-Module-Live- Patching-15-SP7-2026-2929=1 SUSE-SLE-Module-Live-Patching-15-SP7-2026-2921=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_1-debugsource-19-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_6-debugsource-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_6-default-18-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_5-debugsource-11-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_4-debugsource-14-150700.2.2 * kernel-livepatch-6_4_0-150700_51-default-19-150700.3.54.1 * kernel-livepatch-SLE15-SP7_Update_0-debugsource-19-150700.3.54.1 * kernel-livepatch-6_4_0-150700_53_11-default-debuginfo-14-150700.2.2 * kernel-livepatch-6_4_0-150700_53_3-default-19-150700.2.2 * kernel-livepatch-6_4_0-150700_53_16-default-14-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_2-debugsource-18-150700.2.2 * kernel-livepatch-6_4_0-150700_53_16-default-debuginfo-14-150700.2.2 * kernel-livepatch-6_4_0-150700_53_11-default-14-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_3-debugsource-14-150700.2.2 * kernel-livepatch-6_4_0-150700_53_6-default-debuginfo-18-150700.2.2 * kernel-livepatch-6_4_0-150700_51-default-debuginfo-19-150700.3.54.1 * kernel-livepatch-6_4_0-150700_53_19-default-debuginfo-11-150700.2.2 * kernel-livepatch-6_4_0-150700_53_22-default-debuginfo-9-150700.2.2 * kernel-livepatch-6_4_0-150700_53_3-default-debuginfo-19-150700.2.2 * kernel-livepatch-6_4_0-150700_53_19-default-11-150700.2.2 * kernel-livepatch-6_4_0-150700_53_22-default-9-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2025-71089.html * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1256615 * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:33:03 -0000 Subject: SUSE-SU-2026:2931-1: moderate: Security update for libslirp Message-ID: <178401798303.27.17204226345843554204@178315a69387> # Security update for libslirp Announcement ID: SUSE-SU-2026:2931-1 Release Date: 2026-07-13T18:43:58Z Rating: moderate References: * bsc#1268903 Cross-References: * CVE-2026-9539 CVSS scores: * CVE-2026-9539 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-9539 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libslirp fixes the following issues: * CVE-2026-9539: TCP URG out of bounds heap read information leak (bsc#1268903). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2931=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2931=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2931=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libslirp-devel-4.7.0+44-150500.4.3.1 * libslirp-debugsource-4.7.0+44-150500.4.3.1 * libslirp0-debuginfo-4.7.0+44-150500.4.3.1 * libslirp0-4.7.0+44-150500.4.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libslirp-devel-4.7.0+44-150500.4.3.1 * libslirp0-debuginfo-4.7.0+44-150500.4.3.1 * libslirp0-4.7.0+44-150500.4.3.1 * libslirp-debugsource-4.7.0+44-150500.4.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libslirp0-4.7.0+44-150500.4.3.1 * libslirp-debugsource-4.7.0+44-150500.4.3.1 * libslirp0-debuginfo-4.7.0+44-150500.4.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-9539.html * https://bugzilla.suse.com/show_bug.cgi?id=1268903 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:33:24 -0000 Subject: SUSE-SU-2026:2926-1: important: Security update for curl Message-ID: <178401800400.27.16437223679513217480@178315a69387> # Security update for curl Announcement ID: SUSE-SU-2026:2926-1 Release Date: 2026-07-13T17:55:14Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2926=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2926=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2926=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * curl-mini-debugsource-8.14.1-150600.4.46.1 * libcurl4-8.14.1-150600.4.46.1 * libcurl-mini4-8.14.1-150600.4.46.1 * curl-8.14.1-150600.4.46.1 * libcurl4-debuginfo-8.14.1-150600.4.46.1 * libcurl-mini4-debuginfo-8.14.1-150600.4.46.1 * curl-debugsource-8.14.1-150600.4.46.1 * curl-debuginfo-8.14.1-150600.4.46.1 * libcurl-devel-8.14.1-150600.4.46.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libcurl-devel-64bit-8.14.1-150600.4.46.1 * libcurl4-64bit-8.14.1-150600.4.46.1 * libcurl4-64bit-debuginfo-8.14.1-150600.4.46.1 * openSUSE Leap 15.6 (x86_64) * libcurl4-32bit-8.14.1-150600.4.46.1 * libcurl-devel-32bit-8.14.1-150600.4.46.1 * libcurl4-32bit-debuginfo-8.14.1-150600.4.46.1 * openSUSE Leap 15.6 (noarch) * curl-zsh-completion-8.14.1-150600.4.46.1 * libcurl-devel-doc-8.14.1-150600.4.46.1 * curl-fish-completion-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150600.4.46.1 * curl-8.14.1-150600.4.46.1 * libcurl4-debuginfo-8.14.1-150600.4.46.1 * curl-debugsource-8.14.1-150600.4.46.1 * libcurl-devel-8.14.1-150600.4.46.1 * curl-debuginfo-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libcurl4-32bit-8.14.1-150600.4.46.1 * libcurl4-32bit-debuginfo-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libcurl4-8.14.1-150600.4.46.1 * curl-8.14.1-150600.4.46.1 * libcurl4-debuginfo-8.14.1-150600.4.46.1 * curl-debugsource-8.14.1-150600.4.46.1 * curl-debuginfo-8.14.1-150600.4.46.1 * libcurl-devel-8.14.1-150600.4.46.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.46.1 * libcurl4-32bit-8.14.1-150600.4.46.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:33:46 -0000 Subject: SUSE-SU-2026:2925-1: important: Security update for curl Message-ID: <178401802615.27.16252792945947482213@178315a69387> # Security update for curl Announcement ID: SUSE-SU-2026:2925-1 Release Date: 2026-07-13T17:53:33Z Rating: important References: * bsc#1262631 * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-4873 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4873 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-4873 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-4873 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-4873: connection reuse ignores TLS requirement (bsc#1262631). * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2925=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcurl-devel-8.14.1-150700.7.20.1 * curl-8.14.1-150700.7.20.1 * libcurl4-debuginfo-8.14.1-150700.7.20.1 * curl-debuginfo-8.14.1-150700.7.20.1 * libcurl4-8.14.1-150700.7.20.1 * curl-debugsource-8.14.1-150700.7.20.1 * Basesystem Module 15-SP7 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150700.7.20.1 * libcurl4-32bit-8.14.1-150700.7.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-4873.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1262631 * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:33:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:33:59 -0000 Subject: SUSE-SU-2026:2924-1: moderate: Security update for gnutls Message-ID: <178401803986.27.17637860628807672216@178315a69387> # Security update for gnutls Announcement ID: SUSE-SU-2026:2924-1 Release Date: 2026-07-13T17:51:20Z Rating: moderate References: * bsc#1263707 * bsc#1263710 * bsc#1263712 * bsc#1263713 * bsc#1263714 * bsc#1263715 Cross-References: * CVE-2026-3833 * CVE-2026-42011 * CVE-2026-42013 * CVE-2026-42014 * CVE-2026-42015 * CVE-2026-5260 CVSS scores: * CVE-2026-3833 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3833 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-3833 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42011 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42013 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42013 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-42015 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42015 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-42015 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5260 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5260 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5260 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for gnutls fixes the following issues * CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707). * CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715). * CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710). * CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712). * CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713). * CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2924=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libgnutls-openssl27-3.3.27-3.21.1 * libgnutls-devel-3.3.27-3.21.1 * libgnutls28-32bit-3.3.27-3.21.1 * libgnutls28-3.3.27-3.21.1 * gnutls-debugsource-3.3.27-3.21.1 * gnutls-3.3.27-3.21.1 * gnutls-debuginfo-3.3.27-3.21.1 * libgnutls28-debuginfo-32bit-3.3.27-3.21.1 * libgnutls-openssl27-debuginfo-3.3.27-3.21.1 * libgnutls28-debuginfo-3.3.27-3.21.1 * libgnutlsxx-devel-3.3.27-3.21.1 * libgnutls-openssl-devel-3.3.27-3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3833.html * https://www.suse.com/security/cve/CVE-2026-42011.html * https://www.suse.com/security/cve/CVE-2026-42013.html * https://www.suse.com/security/cve/CVE-2026-42014.html * https://www.suse.com/security/cve/CVE-2026-42015.html * https://www.suse.com/security/cve/CVE-2026-5260.html * https://bugzilla.suse.com/show_bug.cgi?id=1263707 * https://bugzilla.suse.com/show_bug.cgi?id=1263710 * https://bugzilla.suse.com/show_bug.cgi?id=1263712 * https://bugzilla.suse.com/show_bug.cgi?id=1263713 * https://bugzilla.suse.com/show_bug.cgi?id=1263714 * https://bugzilla.suse.com/show_bug.cgi?id=1263715 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:34:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:34:13 -0000 Subject: SUSE-SU-2026:2923-1: moderate: Security update for gnutls Message-ID: <178401805313.27.3021669674474718701@178315a69387> # Security update for gnutls Announcement ID: SUSE-SU-2026:2923-1 Release Date: 2026-07-13T17:49:40Z Rating: moderate References: * bsc#1263707 * bsc#1263710 * bsc#1263712 * bsc#1263713 * bsc#1263714 * bsc#1263715 Cross-References: * CVE-2026-3833 * CVE-2026-42011 * CVE-2026-42013 * CVE-2026-42014 * CVE-2026-42015 * CVE-2026-5260 CVSS scores: * CVE-2026-3833 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3833 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3833 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-3833 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42011 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-42011 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42013 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42013 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42013 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-42015 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42015 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-42015 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-5260 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-5260 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-5260 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for gnutls fixes the following issues * CVE-2026-3833: incorrectly accepted domain names due to comparison during name constraints processing being case-sensitive (bsc#1263707). * CVE-2026-5260: heap overread when processing extremely short premaster secret as part of an RSA key exchange (bsc#1263715). * CVE-2026-42011: name constraint bypass leading to acceptance of invalid certificates during certificate validation (bsc#1263710). * CVE-2026-42013: certificate validation bypass when validating certificates with an oversized SAN (bsc#1263712). * CVE-2026-42014: use-after-free when an attacker attempts to change the PIN with a NULL old PIN for a token that lacks a protected authentication path (bsc#1263713). * CVE-2026-42015: memory corruption when appending to a PKCS#12 bag that already contains 32 elements (bsc#1263714). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2923=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gnutls-debugsource-3.4.17-8.26.1 * libgnutls30-debuginfo-32bit-3.4.17-8.26.1 * libgnutls30-3.4.17-8.26.1 * libgnutls30-debuginfo-3.4.17-8.26.1 * libgnutls30-32bit-3.4.17-8.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3833.html * https://www.suse.com/security/cve/CVE-2026-42011.html * https://www.suse.com/security/cve/CVE-2026-42013.html * https://www.suse.com/security/cve/CVE-2026-42014.html * https://www.suse.com/security/cve/CVE-2026-42015.html * https://www.suse.com/security/cve/CVE-2026-5260.html * https://bugzilla.suse.com/show_bug.cgi?id=1263707 * https://bugzilla.suse.com/show_bug.cgi?id=1263710 * https://bugzilla.suse.com/show_bug.cgi?id=1263712 * https://bugzilla.suse.com/show_bug.cgi?id=1263713 * https://bugzilla.suse.com/show_bug.cgi?id=1263714 * https://bugzilla.suse.com/show_bug.cgi?id=1263715 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 08:34:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 08:34:23 -0000 Subject: SUSE-SU-2026:2922-1: low: Security update for patch Message-ID: <178401806337.27.6865530376731906496@178315a69387> # Security update for patch Announcement ID: SUSE-SU-2026:2922-1 Release Date: 2026-07-13T17:47:13Z Rating: low References: * bsc#1194037 * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2021-45261 * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2021-45261 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2021-45261 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2021-45261: Invalid Pointer via another_hunk function (bsc#1194037). * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2922=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * patch-2.7.5-8.14.1 * patch-debugsource-2.7.5-8.14.1 * patch-debuginfo-2.7.5-8.14.1 ## References: * https://www.suse.com/security/cve/CVE-2021-45261.html * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1194037 * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:30:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 12:30:49 -0000 Subject: SUSE-SU-2026:2945-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Message-ID: <178403224975.94.12671056861126252636@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2945-1 Release Date: 2026-07-14T06:15:48Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.34 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2946=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2945=1 SUSE-2026-2944=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2944=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2945=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_25-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-4-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-4-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-4-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_25-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-4-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_109-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-4-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-4-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_34-default-6-150700.2.2 * kernel-livepatch-6_4_0-150700_53_34-default-debuginfo-6-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_10-debugsource-6-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:31:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 12:31:31 -0000 Subject: SUSE-SU-2026:2943-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Message-ID: <178403229153.94.3128468496631121425@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2943-1 Release Date: 2026-07-14T06:15:15Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.52 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2943=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_14-debugsource-3-150700.2.2 * kernel-livepatch-6_4_0-150700_53_52-default-3-150700.2.2 * kernel-livepatch-6_4_0-150700_53_52-default-debuginfo-3-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:32:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 12:32:10 -0000 Subject: SUSE-SU-2026:2938-1: important: Security update for the Linux Kernel (Live Patch 38 for SUSE Linux Enterprise 15 SP5) Message-ID: <178403233028.94.13669779285117424648@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 38 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2938-1 Release Date: 2026-07-14T04:32:24Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.149 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2940=1 SUSE-SLE- Module-Live-Patching-15-SP5-2026-2941=1 SUSE-SLE-Module-Live- Patching-15-SP5-2026-2938=1 SUSE-SLE-Module-Live-Patching-15-SP5-2026-2939=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2940=1 SUSE-2026-2941=1 SUSE-2026-2938=1 SUSE-2026-2939=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-5-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_149-default-5-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-5-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-9-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-5-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_149-default-5-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-9-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_141-default-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-6-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-5-150500.2.2 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-6-150500.2.2 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-9-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:32:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 12:32:45 -0000 Subject: SUSE-SU-2026:2937-1: important: Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4) Message-ID: <178403236558.94.1960938402325509492@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 53 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2937-1 Release Date: 2026-07-13T21:16:08Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.214 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2937=1 SUSE-2026-2936=1 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2937=1 SUSE-SLE- Module-Live-Patching-15-SP4-2026-2936=1 ## Package List: * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_214-default-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-3-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_214-default-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-3-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 12:32:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 12:32:50 -0000 Subject: SUSE-SU-2026:2942-1: important: Security update for kubernetes Message-ID: <178403237003.94.338422918542410406@1437f03ce14a> # Security update for kubernetes Announcement ID: SUSE-SU-2026:2942-1 Release Date: 2026-07-14T06:10:19Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for kubernetes rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2942=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2942=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kubernetes1.35-client-1.35.4-150600.13.36.1 * kubernetes1.35-client-common-1.35.4-150600.13.36.1 * openSUSE Leap 15.6 (noarch) * kubernetes1.35-client-bash-completion-1.35.4-150600.13.36.1 * kubernetes1.35-client-fish-completion-1.35.4-150600.13.36.1 * Containers Module 15-SP7 (noarch) * kubernetes1.35-client-bash-completion-1.35.4-150600.13.36.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kubernetes1.35-client-1.35.4-150600.13.36.1 * kubernetes1.35-client-common-1.35.4-150600.13.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:30:19 -0000 Subject: SUSE-SU-2026:22587-1: important: Security update for haproxy Message-ID: <178404661905.143.4080568582624179017@178315a69387> # Security update for haproxy Announcement ID: SUSE-SU-2026:22587-1 Release Date: 2026-07-07T10:11:29Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * Update to version 3.2.21+git0.dbe43be37 * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1166=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * haproxy-debuginfo-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debugsource-3.2.21+git0.dbe43be37-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:30:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:30:59 -0000 Subject: SUSE-SU-2026:22583-1: important: Security update for rust-keylime Message-ID: <178404665970.143.5811490271746367373@178315a69387> # Security update for rust-keylime Announcement ID: SUSE-SU-2026:22583-1 Release Date: 2026-07-09T09:06:27Z Rating: important References: * bsc#1260596 * bsc#1270174 * bsc#1270523 * bsc#1270614 * bsc#1270699 * bsc#1270792 * bsc#1270842 * bsc#1270903 * bsc#1270999 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for rust-keylime fixes the following issues: Update to version 0.2.9+49. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270174). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270614). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270699). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270792). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270842). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270523). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270903). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270999). Other updates and bugfixes: * Update openssl to 0.10.81. * Make tss-esai-sys depend on bindgen 72.1 to support llvm > 21. * Build with Clang <= 21 (bsc#1260596). * Version 0.2.9+49: * build(deps): bump uuid from 1.23.3 to 1.23.4 * build(deps): bump syn from 2.0.117 to 2.0.118 * build(deps): bump openssl from 0.10.80 to 0.10.81 * build(deps): bump rand from 0.9.4 to 0.10.1 * Added new regression test into packit-ci.yaml * build(deps): bump actions/checkout from 6 to 7 * build(deps): bump uuid from 1.23.1 to 1.23.3 * build(deps): bump log from 0.4.29 to 0.4.32 * build(deps): bump http from 1.4.0 to 1.4.2 * build(deps): bump codecov/codecov-action from 6 to 7 * build(deps): bump retry-policies from 0.5.1 to 0.5.2 * fix: Remove unused base64::Engine import in context_info tests * build(deps): bump reqwest-middleware from 0.5.1 to 0.5.2 * build(deps): bump serde_json from 1.0.149 to 1.0.150 * build(deps): bump openssl from 0.10.79 to 0.10.80 * agent: Hash agent ID before TPM2_Certify qualifying data * cargo: Bump tss-esapi, picky-asn1-x509, and picky-asn1-der * build(deps): bump openssl from 0.10.78 to 0.10.79 * build(deps): bump once_cell from 1.21.3 to 1.21.4 * build(deps): bump tempfile from 3.23.0 to 3.27.0 * push-model: cache UEFI event log bytes at startup * build(deps): bump quote from 1.0.40 to 1.0.45 * build(deps): bump chrono from 0.4.42 to 0.4.44 * build(deps): bump openssl from 0.10.73 to 0.10.78 * build(deps): bump serde_json from 1.0.143 to 1.0.149 * build(deps): bump syn from 2.0.106 to 2.0.117 * build(deps): bump libc from 0.2.175 to 0.2.184 * build(deps): bump rand from 0.9.2 to 0.9.4 * Version 0.2.9+21: * tests: use Express-style named params in Mockoon endpoints * build(deps): bump pest_derive from 2.8.1 to 2.8.6 * build(deps): bump trybuild from 1.0.110 to 1.0.115 * build(deps): bump log from 0.4.28 to 0.4.29 * build(deps): bump uuid from 1.19.0 to 1.20.0 * build(deps): bump codecov/codecov-action from 5 to 6 * build(deps): bump tracing-subscriber from 0.3.20 to 0.3.23 * build(deps): bump cfg-if from 1.0.3 to 1.0.4 * build(deps): bump tokio from 1.49.0 to 1.50.0 * build(deps): bump actix-web from 4.12.1 to 4.13.0 * build(deps): bump anyhow from 1.0.99 to 1.0.102 * build(deps): bump clap from 4.5.57 to 4.5.60 * build(deps): bump tracing from 0.1.36 to 0.1.44 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1190=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1190=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rust-keylime-debuginfo-0.2.9+49-160000.1.1 * keylime-ima-policy-0.2.9+49-160000.1.1 * rust-keylime-0.2.9+49-160000.1.1 * rust-keylime-debugsource-0.2.9+49-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rust-keylime-debuginfo-0.2.9+49-160000.1.1 * keylime-ima-policy-0.2.9+49-160000.1.1 * rust-keylime-0.2.9+49-160000.1.1 * rust-keylime-debugsource-0.2.9+49-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1260596 * https://bugzilla.suse.com/show_bug.cgi?id=1270174 * https://bugzilla.suse.com/show_bug.cgi?id=1270523 * https://bugzilla.suse.com/show_bug.cgi?id=1270614 * https://bugzilla.suse.com/show_bug.cgi?id=1270699 * https://bugzilla.suse.com/show_bug.cgi?id=1270792 * https://bugzilla.suse.com/show_bug.cgi?id=1270842 * https://bugzilla.suse.com/show_bug.cgi?id=1270903 * https://bugzilla.suse.com/show_bug.cgi?id=1270999 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:31:18 -0000 Subject: SUSE-SU-2026:22582-1: important: Security update for curl Message-ID: <178404667841.143.8855191736194126083@178315a69387> # Security update for curl Announcement ID: SUSE-SU-2026:22582-1 Release Date: 2026-07-08T13:46:40Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1187=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1187=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libcurl4-debuginfo-8.14.1-160000.8.1 * curl-8.14.1-160000.8.1 * curl-debuginfo-8.14.1-160000.8.1 * libcurl-mini4-debuginfo-8.14.1-160000.8.1 * curl-debugsource-8.14.1-160000.8.1 * libcurl-mini4-8.14.1-160000.8.1 * curl-mini-debugsource-8.14.1-160000.8.1 * libcurl-devel-8.14.1-160000.8.1 * libcurl4-8.14.1-160000.8.1 * SUSE Linux Enterprise Server 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.8.1 * libcurl-devel-doc-8.14.1-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libcurl4-debuginfo-8.14.1-160000.8.1 * curl-8.14.1-160000.8.1 * curl-debuginfo-8.14.1-160000.8.1 * curl-mini-debugsource-8.14.1-160000.8.1 * curl-debugsource-8.14.1-160000.8.1 * libcurl-devel-8.14.1-160000.8.1 * libcurl-mini4-8.14.1-160000.8.1 * libcurl-mini4-debuginfo-8.14.1-160000.8.1 * libcurl4-8.14.1-160000.8.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * curl-zsh-completion-8.14.1-160000.8.1 * libcurl-devel-doc-8.14.1-160000.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:31:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:31:57 -0000 Subject: SUSE-SU-2026:22576-1: important: Security update for qemu Message-ID: <178404671735.143.11300164633608141900@178315a69387> # Security update for qemu Announcement ID: SUSE-SU-2026:22576-1 Release Date: 2026-07-07T17:20:48Z Rating: important References: * bsc#1199023 * bsc#1268061 * bsc#1268279 * bsc#1268794 * bsc#1270133 * jsc#PED-9266 Cross-References: * CVE-2026-3886 * CVE-2026-48004 * CVE-2026-48914 CVSS scores: * CVE-2026-3886 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48914 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2026-48914 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities, contains one feature and has two fixes can now be installed. ## Description: This update for qemu fixes the following issues: Update to version 10.0.11. Security issues fixed: * CVE-2026-3886: integer overflow leading to privilege escalation due to lack of proper validation of user-supplied data in the virtio-gpu driver (bsc#1268061). * CVE-2026-48914: heap buffer overflow due to improper size validation in virtio-blk SCSI request handling (bsc#1268794). * CVE-2026-48004: heap use-after-free race condition due to missing rename lock in v9fs_co_readdir_many (bsc#1270133). Other updates and bugfixes: * Version 10.0.11: * Full backport list here: https://lore.kernel.org/qemu- devel/20260627082646.D825717AB67 at think4mjt.localdomain/ * Version 10.0.10: * Full backport list here: https://lore.kernel.org/qemu- devel/20260528061820.CEE521691A9 at think4mjt.localdomain/ * ppc/spapr: Skip system reset for quiesced CPUs (bsc#1268279). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * i386/tdx: handle TDG.VP.VMCALL (jsc#PED-9266). * update Linux headers to v6.16-rc3 (jsc#PED-9266). * i386/cpu: Warn about why CPUID_EXT_PDCM is not available (jsc#PED-9266). * i386/cpu: Move adjustment of CPUID_EXT_PDCM before feature_dependencies[] check (jsc#PED-9266). * [openSUSE] qemu-ga: fix service file against no-autostart (bsc#1199023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1174=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1174=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * qemu-ppc-10.0.11-160000.1.1 * qemu-audio-alsa-10.0.11-160000.1.1 * qemu-arm-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-10.0.11-160000.1.1 * qemu-extra-10.0.11-160000.1.1 * qemu-img-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-10.0.11-160000.1.1 * qemu-debugsource-10.0.11-160000.1.1 * qemu-audio-oss-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-10.0.11-160000.1.1 * qemu-tools-10.0.11-160000.1.1 * qemu-debuginfo-10.0.11-160000.1.1 * qemu-arm-10.0.11-160000.1.1 * qemu-linux-user-10.0.11-160000.1.1 * qemu-s390x-10.0.11-160000.1.1 * qemu-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-10.0.11-160000.1.1 * qemu-guest-agent-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-10.0.11-160000.1.1 * qemu-vhost-user-gpu-10.0.11-160000.1.1 * qemu-block-iscsi-10.0.11-160000.1.1 * qemu-headless-10.0.11-160000.1.1 * qemu-audio-jack-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-redirect-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-debuginfo-10.0.11-160000.1.1 * qemu-extra-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1 * qemu-block-nfs-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-10.0.11-160000.1.1 * qemu-audio-alsa-debuginfo-10.0.11-160000.1.1 * qemu-ksm-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-10.0.11-160000.1.1 * qemu-hw-usb-redirect-10.0.11-160000.1.1 * qemu-x86-10.0.11-160000.1.1 * qemu-vhost-user-gpu-debuginfo-10.0.11-160000.1.1 * qemu-block-nfs-10.0.11-160000.1.1 * qemu-block-curl-debuginfo-10.0.11-160000.1.1 * qemu-s390x-debuginfo-10.0.11-160000.1.1 * qemu-block-iscsi-debuginfo-10.0.11-160000.1.1 * qemu-tools-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-debuginfo-10.0.11-160000.1.1 * qemu-pr-helper-10.0.11-160000.1.1 * qemu-block-dmg-10.0.11-160000.1.1 * qemu-block-curl-10.0.11-160000.1.1 * qemu-x86-debuginfo-10.0.11-160000.1.1 * qemu-hw-usb-host-10.0.11-160000.1.1 * qemu-block-dmg-debuginfo-10.0.11-160000.1.1 * qemu-ppc-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-10.0.11-160000.1.1 * qemu-audio-oss-10.0.11-160000.1.1 * qemu-guest-agent-debuginfo-10.0.11-160000.1.1 * qemu-audio-jack-debuginfo-10.0.11-160000.1.1 * qemu-pr-helper-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debugsource-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-debuginfo-10.0.11-160000.1.1 * qemu-img-10.0.11-160000.1.1 * qemu-hw-usb-host-debuginfo-10.0.11-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * qemu-SLOF-10.0.11-160000.1.1 * qemu-skiboot-10.0.11-160000.1.1 * qemu-ipxe-10.0.11-160000.1.1 * qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-doc-10.0.11-160000.1.1 * qemu-microvm-10.0.11-160000.1.1 * qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-lang-10.0.11-160000.1.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * qemu-vmsr-helper-10.0.11-160000.1.1 * qemu-vmsr-helper-debuginfo-10.0.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * qemu-ppc-10.0.11-160000.1.1 * qemu-audio-alsa-10.0.11-160000.1.1 * qemu-arm-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-10.0.11-160000.1.1 * qemu-extra-10.0.11-160000.1.1 * qemu-img-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-10.0.11-160000.1.1 * qemu-debugsource-10.0.11-160000.1.1 * qemu-audio-oss-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-10.0.11-160000.1.1 * qemu-tools-10.0.11-160000.1.1 * qemu-debuginfo-10.0.11-160000.1.1 * qemu-arm-10.0.11-160000.1.1 * qemu-linux-user-10.0.11-160000.1.1 * qemu-s390x-10.0.11-160000.1.1 * qemu-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-10.0.11-160000.1.1 * qemu-guest-agent-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-10.0.11-160000.1.1 * qemu-audio-jack-10.0.11-160000.1.1 * qemu-vhost-user-gpu-10.0.11-160000.1.1 * qemu-hw-display-virtio-vga-debuginfo-10.0.11-160000.1.1 * qemu-block-iscsi-10.0.11-160000.1.1 * qemu-hw-usb-redirect-debuginfo-10.0.11-160000.1.1 * qemu-audio-dbus-debuginfo-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-pci-10.0.11-160000.1.1 * qemu-block-nfs-debuginfo-10.0.11-160000.1.1 * qemu-extra-debuginfo-10.0.11-160000.1.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-10.0.11-160000.1.1 * qemu-audio-alsa-debuginfo-10.0.11-160000.1.1 * qemu-ksm-10.0.11-160000.1.1 * qemu-hw-display-virtio-gpu-10.0.11-160000.1.1 * qemu-hw-usb-redirect-10.0.11-160000.1.1 * qemu-x86-10.0.11-160000.1.1 * qemu-block-iscsi-debuginfo-10.0.11-160000.1.1 * qemu-vhost-user-gpu-debuginfo-10.0.11-160000.1.1 * qemu-s390x-debuginfo-10.0.11-160000.1.1 * qemu-block-curl-debuginfo-10.0.11-160000.1.1 * qemu-block-nfs-10.0.11-160000.1.1 * qemu-tools-debuginfo-10.0.11-160000.1.1 * qemu-ivshmem-tools-debuginfo-10.0.11-160000.1.1 * qemu-pr-helper-10.0.11-160000.1.1 * qemu-block-curl-10.0.11-160000.1.1 * qemu-block-dmg-10.0.11-160000.1.1 * qemu-hw-usb-host-10.0.11-160000.1.1 * qemu-x86-debuginfo-10.0.11-160000.1.1 * qemu-block-dmg-debuginfo-10.0.11-160000.1.1 * qemu-headless-10.0.11-160000.1.1 * qemu-ppc-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-10.0.11-160000.1.1 * qemu-guest-agent-debuginfo-10.0.11-160000.1.1 * qemu-block-ssh-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debuginfo-10.0.11-160000.1.1 * qemu-audio-oss-10.0.11-160000.1.1 * qemu-pr-helper-debuginfo-10.0.11-160000.1.1 * qemu-audio-jack-debuginfo-10.0.11-160000.1.1 * qemu-linux-user-debugsource-10.0.11-160000.1.1 * qemu-hw-usb-smartcard-debuginfo-10.0.11-160000.1.1 * qemu-img-10.0.11-160000.1.1 * qemu-hw-usb-host-debuginfo-10.0.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * qemu-vgabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-SLOF-10.0.11-160000.1.1 * qemu-skiboot-10.0.11-160000.1.1 * qemu-ipxe-10.0.11-160000.1.1 * qemu-doc-10.0.11-160000.1.1 * qemu-seabios-10.0.111.16.3_3_g3d33c746-160000.1.1 * qemu-microvm-10.0.11-160000.1.1 * qemu-lang-10.0.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * qemu-vmsr-helper-debuginfo-10.0.11-160000.1.1 * qemu-vmsr-helper-10.0.11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3886.html * https://www.suse.com/security/cve/CVE-2026-48004.html * https://www.suse.com/security/cve/CVE-2026-48914.html * https://bugzilla.suse.com/show_bug.cgi?id=1199023 * https://bugzilla.suse.com/show_bug.cgi?id=1268061 * https://bugzilla.suse.com/show_bug.cgi?id=1268279 * https://bugzilla.suse.com/show_bug.cgi?id=1268794 * https://bugzilla.suse.com/show_bug.cgi?id=1270133 * https://jira.suse.com/browse/PED-9266 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:32:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:32:14 -0000 Subject: SUSE-SU-2026:22575-1: important: Security update for alloy Message-ID: <178404673495.143.9772826502193160575@178315a69387> # Security update for alloy Announcement ID: SUSE-SU-2026:22575-1 Release Date: 2026-07-07T17:00:29Z Rating: important References: * bsc#1260981 * bsc#1265440 * bsc#1266196 * bsc#1266654 * bsc#1267185 * bsc#1267333 * bsc#1267481 * bsc#1267485 * bsc#1267488 * bsc#1267489 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33532 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41889 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-45678 * CVE-2026-45682 * CVE-2026-45685 * CVE-2026-45686 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33532 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33532 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33532 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41889 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41889 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41889 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41889 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45678 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45678 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45682 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45682 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45685 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45685 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45686 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45686 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 26 vulnerabilities can now be installed. ## Description: This update for alloy fixes the following issues: Update to version 1.17.0. Security issues fixed: * CVE-2026-25680: golang.org/x/net/html: parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service (bsc#1267185). * CVE-2026-25681: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-27136: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-33532: yaml: parsing input with deeply nestes collections may throw a `RangeError` due to a stack overflow and cause to a denial of service (bsc#1260981). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). * CVE-2026-39827: golang.org/x/crypto/ssh: authenticated SSH clients that repeatedly open channels which were rejected by the server can cause unbounded memory growth and a crash (bsc#1266196). * CVE-2026-39828: golang.org/x/crypto/ssh: permissions discarded when an SSH server authentication callback returns `PartialSuccessError` with non-`nil` permissions (bsc#1266196). * CVE-2026-39829: golang.org/x/crypto/ssh: unenforced size limits on key parameters by the the RSA and DSA public key parsers can lead to excessive CPU consumption when processing a crafted public key (bsc#1266196). * CVE-2026-39830: golang.org/x/crypto/ssh: malicious SSH peers sending unsolicited global request responses can block a connection's read loop and cause a resource leak (bsc#1266196). * CVE-2026-39831: golang.org/x/crypto/ssh: missing `User Presence` flag checks in the `Verify()` method for FIDO/U2F security key types cause signatures generated without physical touch to be accepted (bsc#1266196). * CVE-2026-39832: golang.org/x/crypto/ssh: destination restrictions are silently stripped when forwarding keys and allow for unrestricted use of a key on a remote host (bsc#1266196). * CVE-2026-39833: golang.org/x/crypto/ssh: in-memory keyring returned by `NewKeyring()` silently accepts keys with the `ConfirmBeforeUse` constraint but never enforces it (bsc#1266196). * CVE-2026-39834: golang.org/x/crypto/ssh: writing data larger than 4GB in a single `Write` call on an SSH channel leads to an integer overflow and an infinite loop that sends empty packets (bsc#1266196). * CVE-2026-39835: golang.org/x/crypto/ssh: processing of certificates by SSH servers using `CertChecker` as a public key callback without setting `IsUserAuthority` or `IsHostAuthority` can lead to a panic (bsc#1266196). * CVE-2026-41889: github.com/jackc/pgx/v5/internal/sanitize: use placeholders in dollar-quoted string literals in an SQL query can lead to a SQL injection (bsc#1265440). * CVE-2026-42502: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-42506: golang.org/x/net/html: parsing arbitrary HTML which is then rendered using Render can result in an unexpected HTML tree and allows for XSS (bsc#1267185). * CVE-2026-42508: golang.org/x/crypto/ssh: revoked `SignatureKey`s belonging to a CA are not correctly checked for revocation (bsc#1266196). * CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267333). * CVE-2026-45678: go.opentelemetry.io/obi: Postgres BIND parsing can lead to a panic when malformed payloads are processed (bsc#1267481). * CVE-2026-45682: go.opentelemetry.io/obi: keys not deleted by `CappedConcurrentHashMap` after removals allows repeated connection churn to grow the queue without bound and exhaust heap memory (bsc#1267485). * CVE-2026-45685: go.opentelemetry.io/obi: MongoDB TCP parser panics on malformed wire messages and causes a DoS (bsc#1267488). * CVE-2026-45686: go.opentelemetry.io/obi: integer overflow in memcached text protocol parser can crash the OBI process and cause denial of service (bsc#1267489). * CVE-2026-46595: golang.org/x/crypto/ssh: source-address validation is skipped if any other type of callback is passed other than public key (bsc#1266196). * CVE-2026-46597: golang.org/x/crypto/ssh: incorrectly placed cast from bytes to int in the AES-GCM packet decoder when processing specially crafted input can lead to for server-side panic (bsc#1266196). * CVE-2026-46598: golang.org/x/crypto/ssh: `ed25519.PrivateKey` created by casting malformed wire bytes due to processing of certain crafted inputs can lead to panic when used (bsc#1266196). Other updates and bugfixes: * Version 1.17.0: * Features * Add GraphQL server and `gql` subcommand. * `otelcol`: Add Nginx receiver. * `otelcol.exporter.prometheus`: Convert classic histograms to NHCB. * `database_observability`: Various enhancements for MySQL and Postgres. * `faro.receiver`: Support gzip-compressed request bodies. * Update to Beyla 3.9.8. * Bug Fixes * security: Update `x/crypto`, `x/net`, `jackc/pgx/v5`, and `obi`. * cluster: Fix nodes failing to join the cluster with TLS enabled. * `loki.process`: Fix potential deadlocks and limit stage shutdown. * Update Go to v1.26.4. * Version 1.16.3: * cluster: Fix nodes failing to join the cluster when TLS is enabled. * Version 1.16.2: * `loki.process`: No longer mutate rules in `stage.truncate` causing every config update to reload pipeline when this stage is used. * `loki.process`: Potential deadlock on update with stage and receiver changes. * `otelcol.exporter.awss3`: Add missing `unique_key_func_name` attribute. * Remove dependency on vulnerable `yaml` library. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1172=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1172=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * alloy-debuginfo-1.17.0-160000.1.1 * alloy-1.17.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * alloy-debuginfo-1.17.0-160000.1.1 * alloy-1.17.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33532.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41889.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-45678.html * https://www.suse.com/security/cve/CVE-2026-45682.html * https://www.suse.com/security/cve/CVE-2026-45685.html * https://www.suse.com/security/cve/CVE-2026-45686.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1260981 * https://bugzilla.suse.com/show_bug.cgi?id=1265440 * https://bugzilla.suse.com/show_bug.cgi?id=1266196 * https://bugzilla.suse.com/show_bug.cgi?id=1266654 * https://bugzilla.suse.com/show_bug.cgi?id=1267185 * https://bugzilla.suse.com/show_bug.cgi?id=1267333 * https://bugzilla.suse.com/show_bug.cgi?id=1267481 * https://bugzilla.suse.com/show_bug.cgi?id=1267485 * https://bugzilla.suse.com/show_bug.cgi?id=1267488 * https://bugzilla.suse.com/show_bug.cgi?id=1267489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:32:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:32:29 -0000 Subject: SUSE-SU-2026:22574-1: important: Security update for clamav Message-ID: <178404674989.143.12509173853679358546@178315a69387> # Security update for clamav Announcement ID: SUSE-SU-2026:22574-1 Release Date: 2026-07-07T16:59:27Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: Update to version 1.5.3. Security issues fixed: * CVE-2026-20213: out-of-bounds write due to improper boundary checks for content in PE files during scanning (bsc#1270107). * CVE-2026-20214: out-of-bounds write due to improper boundary checks for content in FSG files during scanning (bsc#1270085). * CVE-2026-20215: out-of-bounds write due to improper boundary checks for content in 7z files during scanning (bsc#1270088). * CVE-2026-20216: denial of service due to improper handling of temporary resources during InstallShield file scanning (bsc#1270089). * CVE-2026-20217: out-of-bounds write due to improper boundary checks for content in PESpin files during scanning (bsc#1270091). * CVE-2026-20243: out-of-bounds write due to improper boundary checks for content in ALZ files during scanning (bsc#1270092). * CVE-2026-20244: integer overflow and DoS due to improper boundary checks for content in DMG files during scanning (bsc#1270106). * CVE-2026-41676: buffer overflow due to missing checks via `Deriver:derive`, `PkeyCtxRef:derive` and OpenSSL 1.1.1 (bsc#1270138). Other updates and bugfixes: * Version 1.5.3: * Fixed a bug in the PESpin unpacker cleanup path that could free pointers into the scanned file buffer and crash the scanner. * Fixed an integer overflow in PE rebuild size calculations that could be reached through a malformed Aspack-packed PE file and lead to a heap buffer overflow write. * Fixed an InstallShield archive extraction limit bypass that could write far more temporary data than intended and exhaust temporary storage. * Fixed an FSG unpacker loop underflow that could write past the section array while scanning a malformed PE file. * Fixed ALZ parser size handling bugs that could cause malformed ALZ archives to panic, abort the scanner, or skip expected scan-limit handling. * Fixed a 7z parser substream count overflow that could under-allocate parser metadata arrays and write past them while reading a malformed archive. * Fixed 32-bit DMG parser size checks that could let a short mish stripe table pass validation and crash 32-bit scanner builds. * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Upgraded the Rust tar dependency to resolve the RUSTSEC-2026-0067 and RUSTSEC-2026-0068 advisories, and upgraded the Rust openssl dependency to resolve CVE-2026-41676. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1173=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1173=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libclamav12-1.5.3-160000.1.1 * clamav-debuginfo-1.5.3-160000.1.1 * clamav-milter-1.5.3-160000.1.1 * libclammspack0-debuginfo-1.5.3-160000.1.1 * clamav-milter-debuginfo-1.5.3-160000.1.1 * clamav-debugsource-1.5.3-160000.1.1 * libclamav12-debuginfo-1.5.3-160000.1.1 * libfreshclam4-1.5.3-160000.1.1 * libclammspack0-1.5.3-160000.1.1 * libfreshclam4-debuginfo-1.5.3-160000.1.1 * clamav-devel-1.5.3-160000.1.1 * clamav-1.5.3-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * clamav-docs-html-1.5.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libclamav12-1.5.3-160000.1.1 * clamav-debuginfo-1.5.3-160000.1.1 * clamav-milter-1.5.3-160000.1.1 * libclammspack0-debuginfo-1.5.3-160000.1.1 * clamav-milter-debuginfo-1.5.3-160000.1.1 * clamav-debugsource-1.5.3-160000.1.1 * libclamav12-debuginfo-1.5.3-160000.1.1 * libfreshclam4-1.5.3-160000.1.1 * libclammspack0-1.5.3-160000.1.1 * libfreshclam4-debuginfo-1.5.3-160000.1.1 * clamav-devel-1.5.3-160000.1.1 * clamav-1.5.3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * clamav-docs-html-1.5.3-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:32:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:32:35 -0000 Subject: SUSE-SU-2026:22573-1: important: Security update for ffmpeg-7 Message-ID: <178404675542.143.13898561185430052362@178315a69387> # Security update for ffmpeg-7 Announcement ID: SUSE-SU-2026:22573-1 Release Date: 2026-07-07T16:58:28Z Rating: important References: * bsc#1262047 * jsc#PED-15827 Cross-References: * CVE-2026-30997 CVSS scores: * CVE-2026-30997 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-30997 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-30997 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and contains one feature can now be installed. ## Description: This update for ffmpeg-7 fixes the following issue: * CVE-2026-30997: out-of-bounds read in the `read_global_param()` function allows for a DoS via crafted input (bsc#1262047). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1179=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1179=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ffmpeg-7-debuginfo-7.1.4-160000.2.1 * libpostproc58-7.1.4-160000.2.1 * libavformat61-7.1.4-160000.2.1 * libswresample5-debuginfo-7.1.4-160000.2.1 * libavutil59-7.1.4-160000.2.1 * libavutil59-debuginfo-7.1.4-160000.2.1 * libavformat61-debuginfo-7.1.4-160000.2.1 * libswresample5-7.1.4-160000.2.1 * libavdevice61-debuginfo-7.1.4-160000.2.1 * libavdevice61-7.1.4-160000.2.1 * libpostproc58-debuginfo-7.1.4-160000.2.1 * libswscale8-7.1.4-160000.2.1 * libswscale8-debuginfo-7.1.4-160000.2.1 * libavcodec61-7.1.4-160000.2.1 * libavfilter10-debuginfo-7.1.4-160000.2.1 * libavfilter10-7.1.4-160000.2.1 * ffmpeg-7-7.1.4-160000.2.1 * libavcodec61-debuginfo-7.1.4-160000.2.1 * ffmpeg-7-debugsource-7.1.4-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ffmpeg-7-debuginfo-7.1.4-160000.2.1 * libpostproc58-7.1.4-160000.2.1 * libavformat61-7.1.4-160000.2.1 * libswresample5-debuginfo-7.1.4-160000.2.1 * libavutil59-7.1.4-160000.2.1 * libavutil59-debuginfo-7.1.4-160000.2.1 * libavformat61-debuginfo-7.1.4-160000.2.1 * libswresample5-7.1.4-160000.2.1 * libavdevice61-debuginfo-7.1.4-160000.2.1 * libavdevice61-7.1.4-160000.2.1 * libpostproc58-debuginfo-7.1.4-160000.2.1 * libswscale8-7.1.4-160000.2.1 * libswscale8-debuginfo-7.1.4-160000.2.1 * libavcodec61-7.1.4-160000.2.1 * libavfilter10-debuginfo-7.1.4-160000.2.1 * libavfilter10-7.1.4-160000.2.1 * ffmpeg-7-7.1.4-160000.2.1 * libavcodec61-debuginfo-7.1.4-160000.2.1 * ffmpeg-7-debugsource-7.1.4-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-30997.html * https://bugzilla.suse.com/show_bug.cgi?id=1262047 * https://jira.suse.com/browse/PED-15827 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:33:16 -0000 Subject: SUSE-SU-2026:22572-1: important: Security update for go1.26-openssl Message-ID: <178404679661.143.14106551783421300905@178315a69387> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:22572-1 Release Date: 2026-07-07T16:57:26Z Rating: important References: * bsc#1170826 * bsc#1245878 * bsc#1255111 * bsc#1261653 * bsc#1261654 * bsc#1261655 * bsc#1261656 * bsc#1261657 * bsc#1261658 * bsc#1261659 * bsc#1261660 * bsc#1261661 * bsc#1261662 * bsc#1264395 * bsc#1264499 * bsc#1264500 * bsc#1264501 * bsc#1264502 * bsc#1264503 * bsc#1264504 * bsc#1264505 * bsc#1264506 * bsc#1264507 * bsc#1264508 * bsc#1264509 * bsc#1267442 * bsc#1267444 * bsc#1267450 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-27140 * CVE-2026-27143 * CVE-2026-27144 * CVE-2026-27145 * CVE-2026-32280 * CVE-2026-32281 * CVE-2026-32282 * CVE-2026-32283 * CVE-2026-32288 * CVE-2026-32289 * CVE-2026-33810 * CVE-2026-33811 * CVE-2026-33814 * CVE-2026-39817 * CVE-2026-39819 * CVE-2026-39820 * CVE-2026-39823 * CVE-2026-39825 * CVE-2026-39826 * CVE-2026-39836 * CVE-2026-42499 * CVE-2026-42501 * CVE-2026-42504 * CVE-2026-42507 CVSS scores: * CVE-2026-27140 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-27143 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32283 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32288 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32289 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33810 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33810 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-33810 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L * CVE-2026-33810 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39823 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39825 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39826 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues: Update to go1.26.4 (bsc#1255111). Security issues fixed: * CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). * CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654). * CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656). * CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657). * CVE-2026-32282: os: `Root.Chmod` can follow symlinks out of the root on Linux (bsc#1261658). * CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659). * CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660). * CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661). * CVE-2026-33810: crypto/x509: excluded DNS constraints not properly applied to wildcard domains (bsc#1261662). * CVE-2026-33811: net: crash when handling long `CNAME` response (bsc#1264508). * CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad `SETTINGS_MAX_FRAME_SIZE` (bsc#1264506). * CVE-2026-39817: cmd/go: `go tool pack` does not sanitize output paths (bsc#1264505). * CVE-2026-39819: cmd/go: `go bug` follows symlinks in predictable temporary filenames (bsc#1264504). * CVE-2026-39820: net/mail: quadratic string concatentation in `consumeComment` (bsc#1264503). * CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). * CVE-2026-39825: net/http/httputil: `ReverseProxy` forwards queries with more than `urlmaxqueryparams` parameters (bsc#1264500). * CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507). * CVE-2026-39836: net: panic in `Dial` and `LookupPort` when handling `NUL` byte on Windows (bsc#1264501). * CVE-2026-42499: net/mail: quadratic string concatenation in `consumePhrase` (bsc#1264502). * CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499). * CVE-2026-42504: mime: quadratic complexity in `WordDecoder.DecodeHeader` (bsc#1267442). * CVE-2026-42507: net/textproto: arbitrary input is included in errors without any escaping (bsc#1267444). Other updates and security fixes: * Go packages miss `binutils-gold` dependency (bsc#1170826). * Drop subpackage `go1.x-libstd` `std` library `.so` refs (jsc#PED-1962). * Use `libalternatives` only on `suse_version >= 1610` and keep `update- alternatives` support for older distributions. * Drop the `update-alternatives` migration path for `libalternatives` builds. * Enable `libalternatives` for SLE16.1 and Tumbleweed (bsc#1245878). * Drop go1.26 dependency on `update-alternatives` (bsc#1264395) * Update to version 1.26.3 cut from the `go1.25-fips-release` branch at the revision tagged `go1.26.3-1-openssl-fips` (jsc#SLE-18320). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1175=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1175=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.4-160000.1.1 * go1.26-openssl-1.26.4-160000.1.1 * go1.26-openssl-doc-1.26.4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-openssl-race-1.26.4-160000.1.1 * go1.26-openssl-1.26.4-160000.1.1 * go1.26-openssl-doc-1.26.4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27140.html * https://www.suse.com/security/cve/CVE-2026-27143.html * https://www.suse.com/security/cve/CVE-2026-27144.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-32280.html * https://www.suse.com/security/cve/CVE-2026-32281.html * https://www.suse.com/security/cve/CVE-2026-32282.html * https://www.suse.com/security/cve/CVE-2026-32283.html * https://www.suse.com/security/cve/CVE-2026-32288.html * https://www.suse.com/security/cve/CVE-2026-32289.html * https://www.suse.com/security/cve/CVE-2026-33810.html * https://www.suse.com/security/cve/CVE-2026-33811.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39817.html * https://www.suse.com/security/cve/CVE-2026-39819.html * https://www.suse.com/security/cve/CVE-2026-39820.html * https://www.suse.com/security/cve/CVE-2026-39823.html * https://www.suse.com/security/cve/CVE-2026-39825.html * https://www.suse.com/security/cve/CVE-2026-39826.html * https://www.suse.com/security/cve/CVE-2026-39836.html * https://www.suse.com/security/cve/CVE-2026-42499.html * https://www.suse.com/security/cve/CVE-2026-42501.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1170826 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1261653 * https://bugzilla.suse.com/show_bug.cgi?id=1261654 * https://bugzilla.suse.com/show_bug.cgi?id=1261655 * https://bugzilla.suse.com/show_bug.cgi?id=1261656 * https://bugzilla.suse.com/show_bug.cgi?id=1261657 * https://bugzilla.suse.com/show_bug.cgi?id=1261658 * https://bugzilla.suse.com/show_bug.cgi?id=1261659 * https://bugzilla.suse.com/show_bug.cgi?id=1261660 * https://bugzilla.suse.com/show_bug.cgi?id=1261661 * https://bugzilla.suse.com/show_bug.cgi?id=1261662 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1264499 * https://bugzilla.suse.com/show_bug.cgi?id=1264500 * https://bugzilla.suse.com/show_bug.cgi?id=1264501 * https://bugzilla.suse.com/show_bug.cgi?id=1264502 * https://bugzilla.suse.com/show_bug.cgi?id=1264503 * https://bugzilla.suse.com/show_bug.cgi?id=1264504 * https://bugzilla.suse.com/show_bug.cgi?id=1264505 * https://bugzilla.suse.com/show_bug.cgi?id=1264506 * https://bugzilla.suse.com/show_bug.cgi?id=1264507 * https://bugzilla.suse.com/show_bug.cgi?id=1264508 * https://bugzilla.suse.com/show_bug.cgi?id=1264509 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:33:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:33:46 -0000 Subject: SUSE-SU-2026:22567-1: important: Security update for docker-compose Message-ID: <178404682642.143.5865273323605735711@178315a69387> # Security update for docker-compose Announcement ID: SUSE-SU-2026:22567-1 Release Date: 2026-07-07T12:35:23Z Rating: important References: * bsc#1239340 * bsc#1239766 * bsc#1265782 * bsc#1266625 Cross-References: * CVE-2025-0495 * CVE-2025-22869 * CVE-2026-33814 * CVE-2026-39821 CVSS scores: * CVE-2025-0495 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2025-0495 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N * CVE-2025-0495 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-22869 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22869 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22869 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for docker-compose fixes the following issues * CVE-2025-0495: buildx: credential leakage to telemetry endpoints when credentials allowed to be set as attribute values in cache-to/cache-from configuration (bsc#1239766). * CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239340). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265782). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1168=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1168=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * docker-compose-2.33.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * docker-compose-2.33.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2025-0495.html * https://www.suse.com/security/cve/CVE-2025-22869.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://bugzilla.suse.com/show_bug.cgi?id=1239340 * https://bugzilla.suse.com/show_bug.cgi?id=1239766 * https://bugzilla.suse.com/show_bug.cgi?id=1265782 * https://bugzilla.suse.com/show_bug.cgi?id=1266625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:34:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:34:07 -0000 Subject: SUSE-SU-2026:22566-1: important: Security update for jq Message-ID: <178404684711.143.5381236642977144230@178315a69387> # Security update for jq Announcement ID: SUSE-SU-2026:22566-1 Release Date: 2026-07-07T12:32:56Z Rating: important References: * bsc#1244116 * bsc#1262043 * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 * bsc#1265060 * bsc#1265061 * bsc#1265062 * bsc#1265070 Cross-References: * CVE-2025-48060 * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-33948 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 * CVE-2026-40612 * CVE-2026-41256 * CVE-2026-41257 * CVE-2026-43894 CVSS scores: * CVE-2025-48060 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-48060 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2025-48060 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-48060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40612 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-40612 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41257 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41257 ( NVD ): 6.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43894 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2025-48060: improper handling of string data in `jv_string_empty` can lead to heap buffer overflow and a crash when processing crafted input (bsc#1244116). * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). * CVE-2026-40612: recursion into nested arrays/objects with no depth limit in `jv_contains` can lead to a C stack exhaustion when processing crafted input (bsc#1265060). * CVE-2026-41256: truncation of top-level jq programs loaded with `-f` and can lead to the execution of unintended programs (bsc#1265061). * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS when processing jq bytecode (bsc#1265062). * CVE-2026-43894: signed integer overflow in the `decNumberFromString` `D2U()` macro can lead to an out-of-bounds memory write when processing large number literals (bsc#1265070). * CVE-2026-33948: improper handling of buffer sizes via `strlen()` instead of `fgets()` in CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1169=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1169=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jq-debugsource-1.7.1-160000.3.1 * jq-debuginfo-1.7.1-160000.3.1 * libjq1-debuginfo-1.7.1-160000.3.1 * libjq1-1.7.1-160000.3.1 * libjq-devel-1.7.1-160000.3.1 * jq-1.7.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jq-debugsource-1.7.1-160000.3.1 * libjq-devel-1.7.1-160000.3.1 * libjq1-debuginfo-1.7.1-160000.3.1 * jq-debuginfo-1.7.1-160000.3.1 * libjq1-1.7.1-160000.3.1 * jq-1.7.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-48060.html * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://www.suse.com/security/cve/CVE-2026-40612.html * https://www.suse.com/security/cve/CVE-2026-41256.html * https://www.suse.com/security/cve/CVE-2026-41257.html * https://www.suse.com/security/cve/CVE-2026-43894.html * https://bugzilla.suse.com/show_bug.cgi?id=1244116 * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 * https://bugzilla.suse.com/show_bug.cgi?id=1265060 * https://bugzilla.suse.com/show_bug.cgi?id=1265061 * https://bugzilla.suse.com/show_bug.cgi?id=1265062 * https://bugzilla.suse.com/show_bug.cgi?id=1265070 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:34:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:34:41 -0000 Subject: SUSE-SU-2026:22565-1: important: Security update for nodejs24 Message-ID: <178404688121.143.8395656021961707318@178315a69387> # Security update for nodejs24 Announcement ID: SUSE-SU-2026:22565-1 Release Date: 2026-07-06T20:22:33Z Rating: important References: * bsc#1259853 * bsc#1262274 * bsc#1266318 * bsc#1268097 * bsc#1268477 * bsc#1268478 * bsc#1268479 * bsc#1268480 * bsc#1268481 * bsc#1268482 * bsc#1268554 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268598 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 * bsc#1269825 Cross-References: * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-2581 * CVE-2026-27135 * CVE-2026-40170 * CVE-2026-42338 * CVE-2026-48615 * CVE-2026-48617 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-6733 * CVE-2026-9496 * CVE-2026-9678 * CVE-2026-9679 CVSS scores: * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2581 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-2581 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42338 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-48615 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48615 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48617 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48617 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-48617 ( NVD ): 1.8 CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-9496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9496 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9678 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9678 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 21 vulnerabilities and has one fix can now be installed. ## Description: This update for nodejs24 fixes the following issues Update to version 24.18.0 (bsc#1269825). Security issues fixed: * CVE-2026-2581: undici: denial of service due to uncontrolled resource consumption (bsc#1268480). * CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9678: undici: information disclosure due to improper `cache- control` header parsing (bsc#1268478). * CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent- decoding (bsc#1268477). * CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header (bsc#1268481). * CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-40170: ngtcp2: qlog `parameters_set` stack buffer overflow (bsc#1262274). * CVE-2026-42338: ip-address: cross-site scripting due to improper HTML escaping of untrusted input (bsc#1268097). * CVE-2026-48615: proxy credentials leaked in `ERR_PROXY_TUNNEL` error message (bsc#1268598). * CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation (bsc#1268554). * CVE-2026-48618: unicode dot separator handling can lead to TLS wildcard- depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: unbounded memory growth in `node:http2` clients via attacker-controlled `ORIGIN` frames (bsc#1268618). * CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: `embedded-nul` hostnames can lead to silent authority rebinding due to `c-string` truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in `http.Agent` (bsc#1268611). * CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different `servername` leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: permission model bypass via `FileHandle.utimes()` in the `promises` API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). Other updates and bugfixes: \- Version 24.18.0: \- doc: update `blockList` stability status to release candidate \- fs: support caller-supplied `readFile()` buffers \- http: close pre-request sockets in `closeIdleConnections` \- loader: implement package maps \- net: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` \- tls: add `certificateCompression` option \- vfs: dispatch `node:fs/promises` to mounted VFS instances \- vfs: add minimal `node:vfs` subsystem \- For changes in older versions, see https://github.com/nodejs/node/releases. \- Remove `update- alternatives` from scriptlets if not available. \- Explicitly `BuildRequire` `update-alternatives` and mark it as being used in post/postun. \- Add `-fno- lifetime-dse` to `CXXFLAGS` to avoid parallel/test-snapshot-reproducible testsuite failure with GCC 16. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1150=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1150=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * nodejs24-docs-24.18.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * nodejs24-debugsource-24.18.0-160000.1.1 * nodejs24-devel-24.18.0-160000.1.1 * nodejs24-24.18.0-160000.1.1 * npm24-24.18.0-160000.1.1 * nodejs24-debuginfo-24.18.0-160000.1.1 * corepack24-24.18.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * nodejs24-debugsource-24.18.0-160000.1.1 * nodejs24-devel-24.18.0-160000.1.1 * nodejs24-24.18.0-160000.1.1 * npm24-24.18.0-160000.1.1 * nodejs24-debuginfo-24.18.0-160000.1.1 * corepack24-24.18.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * nodejs24-docs-24.18.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-2581.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-40170.html * https://www.suse.com/security/cve/CVE-2026-42338.html * https://www.suse.com/security/cve/CVE-2026-48615.html * https://www.suse.com/security/cve/CVE-2026-48617.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-9496.html * https://www.suse.com/security/cve/CVE-2026-9678.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1262274 * https://bugzilla.suse.com/show_bug.cgi?id=1266318 * https://bugzilla.suse.com/show_bug.cgi?id=1268097 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268478 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268480 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268554 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268598 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 * https://bugzilla.suse.com/show_bug.cgi?id=1269825 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:35:03 -0000 Subject: SUSE-SU-2026:22564-1: important: Security update for apache2 Message-ID: <178404690342.143.17939455145972029589@178315a69387> # Security update for apache2 Announcement ID: SUSE-SU-2026:22564-1 Release Date: 2026-07-06T20:21:38Z Rating: important References: * bsc#1267503 * bsc#1267955 * bsc#1267956 * bsc#1267962 * bsc#1267963 * bsc#1267965 * bsc#1267969 * bsc#1267970 * bsc#1267971 * bsc#1267972 * bsc#1267976 * bsc#1267977 * bsc#1267978 Cross-References: * CVE-2026-29167 * CVE-2026-29170 * CVE-2026-34355 * CVE-2026-34356 * CVE-2026-42535 * CVE-2026-42536 * CVE-2026-43951 * CVE-2026-44119 * CVE-2026-44185 * CVE-2026-44186 * CVE-2026-44631 * CVE-2026-48913 * CVE-2026-49975 CVSS scores: * CVE-2026-29167 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-29167 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-29170 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-29170 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-34355 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34355 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34356 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34356 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42535 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-42535 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-42535 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-42536 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42536 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42536 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43951 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-43951 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-43951 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44119 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-44119 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44119 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-44185 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-44185 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44185 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44186 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44186 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44186 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-44631 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44631 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44631 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48913 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48913 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48913 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-49975 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-49975 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49975 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for apache2 fixes the following issues * CVE-2026-29167: mod_ldap per-dir use-after-free (bsc#1267976). * CVE-2026-29170: mod_proxy_ftp XSS (bsc#1267977). * CVE-2026-34355: mod_proxy_html buffer overflow (bsc#1267978). * CVE-2026-34356: malicious backend servers can lead to a heap-based buffer overflow (bsc#1267955). * CVE-2026-42535: malicious path manipulation can lead to child process crashes (bsc#1267956). * CVE-2026-42536: processing untrusted content can lead to a heap-based buffer overflow (bsc#1267962). * CVE-2026-43951: out-of-bound read in `merge_response_headers` can cause crash (bsc#1267963). * CVE-2026-44119: improper privilege management can lead to an unauthorized read (bsc#1267965). * CVE-2026-44185: Stack Buffer Over-Read in mod_ssl OCSP `send_request` (bsc#1267969). * CVE-2026-44186: responses from an attacker-controlled FTP backend can lead to resource exhaustion and a denial of service (bsc#1267970). * CVE-2026-44631: crafted regular expression can lead to a buffer underwrite (bsc#1267971). * CVE-2026-48913: file handle exhaustion during request processing in mod_http2 can lead to a use-after-free (bsc#1267972). * CVE-2026-49975: Fix cookie header accounting against LimitRequestFields (bsc#1267503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1149=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1149=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * apache2-utils-2.4.66-160000.3.1 * apache2-prefork-debuginfo-2.4.66-160000.3.1 * apache2-worker-debuginfo-2.4.66-160000.3.1 * apache2-prefork-debugsource-2.4.66-160000.3.1 * apache2-event-debugsource-2.4.66-160000.3.1 * apache2-prefork-2.4.66-160000.3.1 * apache2-event-debuginfo-2.4.66-160000.3.1 * apache2-debugsource-2.4.66-160000.3.1 * apache2-2.4.66-160000.3.1 * apache2-worker-debugsource-2.4.66-160000.3.1 * apache2-devel-2.4.66-160000.3.1 * apache2-utils-debuginfo-2.4.66-160000.3.1 * apache2-debuginfo-2.4.66-160000.3.1 * apache2-utils-debugsource-2.4.66-160000.3.1 * apache2-event-2.4.66-160000.3.1 * apache2-worker-2.4.66-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * apache2-manual-2.4.66-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * apache2-utils-2.4.66-160000.3.1 * apache2-prefork-debuginfo-2.4.66-160000.3.1 * apache2-worker-debuginfo-2.4.66-160000.3.1 * apache2-prefork-debugsource-2.4.66-160000.3.1 * apache2-event-debugsource-2.4.66-160000.3.1 * apache2-event-2.4.66-160000.3.1 * apache2-event-debuginfo-2.4.66-160000.3.1 * apache2-2.4.66-160000.3.1 * apache2-worker-2.4.66-160000.3.1 * apache2-devel-2.4.66-160000.3.1 * apache2-utils-debuginfo-2.4.66-160000.3.1 * apache2-worker-debugsource-2.4.66-160000.3.1 * apache2-debuginfo-2.4.66-160000.3.1 * apache2-utils-debugsource-2.4.66-160000.3.1 * apache2-debugsource-2.4.66-160000.3.1 * apache2-prefork-2.4.66-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * apache2-manual-2.4.66-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-29167.html * https://www.suse.com/security/cve/CVE-2026-29170.html * https://www.suse.com/security/cve/CVE-2026-34355.html * https://www.suse.com/security/cve/CVE-2026-34356.html * https://www.suse.com/security/cve/CVE-2026-42535.html * https://www.suse.com/security/cve/CVE-2026-42536.html * https://www.suse.com/security/cve/CVE-2026-43951.html * https://www.suse.com/security/cve/CVE-2026-44119.html * https://www.suse.com/security/cve/CVE-2026-44185.html * https://www.suse.com/security/cve/CVE-2026-44186.html * https://www.suse.com/security/cve/CVE-2026-44631.html * https://www.suse.com/security/cve/CVE-2026-48913.html * https://www.suse.com/security/cve/CVE-2026-49975.html * https://bugzilla.suse.com/show_bug.cgi?id=1267503 * https://bugzilla.suse.com/show_bug.cgi?id=1267955 * https://bugzilla.suse.com/show_bug.cgi?id=1267956 * https://bugzilla.suse.com/show_bug.cgi?id=1267962 * https://bugzilla.suse.com/show_bug.cgi?id=1267963 * https://bugzilla.suse.com/show_bug.cgi?id=1267965 * https://bugzilla.suse.com/show_bug.cgi?id=1267969 * https://bugzilla.suse.com/show_bug.cgi?id=1267970 * https://bugzilla.suse.com/show_bug.cgi?id=1267971 * https://bugzilla.suse.com/show_bug.cgi?id=1267972 * https://bugzilla.suse.com/show_bug.cgi?id=1267976 * https://bugzilla.suse.com/show_bug.cgi?id=1267977 * https://bugzilla.suse.com/show_bug.cgi?id=1267978 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:35:13 -0000 Subject: SUSE-SU-2026:22562-1: moderate: Security update for jline3 Message-ID: <178404691309.143.4036778493681484634@178315a69387> # Security update for jline3 Announcement ID: SUSE-SU-2026:22562-1 Release Date: 2026-07-06T20:10:17Z Rating: moderate References: * bsc#1269021 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for jline3 fixes the following issues: Changes in jline3: * unauthenticated remote memory exhaustion via unbounded Telnet 'NEW-ENVIRON variables (bsc#1269021) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1148=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1148=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * jline3-curses-3.30.13-160000.3.2 * jline3-terminal-jni-3.30.13-160000.3.2 * jline3-console-ui-3.30.13-160000.3.2 * jline3-remote-telnet-3.30.13-160000.3.2 * jline3-style-3.30.13-160000.3.2 * jline3-javadoc-3.30.13-160000.3.2 * jline3-terminal-jansi-3.30.13-160000.3.2 * jline3-jansi-core-3.30.13-160000.3.2 * jline3-terminal-3.30.13-160000.3.2 * jline3-console-3.30.13-160000.3.2 * jline3-terminal-jna-3.30.13-160000.3.2 * jline3-reader-3.30.13-160000.3.2 * jline3-builtins-3.30.13-160000.3.2 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jline3-3.30.13-160000.3.2 * jline3-jansi-3.30.13-160000.3.2 * jline3-debugsource-3.30.13-160000.3.2 * jline3-native-3.30.13-160000.3.2 * jline3-native-debuginfo-3.30.13-160000.3.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * jline3-terminal-jni-3.30.13-160000.3.2 * jline3-curses-3.30.13-160000.3.2 * jline3-console-ui-3.30.13-160000.3.2 * jline3-remote-telnet-3.30.13-160000.3.2 * jline3-style-3.30.13-160000.3.2 * jline3-javadoc-3.30.13-160000.3.2 * jline3-terminal-jansi-3.30.13-160000.3.2 * jline3-jansi-core-3.30.13-160000.3.2 * jline3-terminal-3.30.13-160000.3.2 * jline3-console-3.30.13-160000.3.2 * jline3-terminal-jna-3.30.13-160000.3.2 * jline3-reader-3.30.13-160000.3.2 * jline3-builtins-3.30.13-160000.3.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jline3-3.30.13-160000.3.2 * jline3-jansi-3.30.13-160000.3.2 * jline3-debugsource-3.30.13-160000.3.2 * jline3-native-3.30.13-160000.3.2 * jline3-native-debuginfo-3.30.13-160000.3.2 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1269021 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:35:18 -0000 Subject: SUSE-SU-2026:22561-1: moderate: Security update for dhcpcd Message-ID: <178404691898.143.14637521938049142957@178315a69387> # Security update for dhcpcd Announcement ID: SUSE-SU-2026:22561-1 Release Date: 2026-07-06T20:10:17Z Rating: moderate References: * bsc#1268761 Cross-References: * CVE-2025-70102 CVSS scores: * CVE-2025-70102 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-70102 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-70102 ( NVD ): 6.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for dhcpcd fixes the following issue Update to 10.3.2: * CVE-2025-70102: NULL pointer dereference in `parse_option()` when processing a specially crafted configuration input (bsc#1268761). Changes for dhcpcd: * options: Ensure ldop is not NULL dereferenced * DHCP: Don't run double EXPIRE hooks on carrier loss * DHCP: free the state when dropping on state NONE * BSD: don't send uninitialised memory using ps_root_indirectioctl * Fix fallback_time option * IPv4: Ignore DHCP state when building routes * route: Routes may not have an interface assinged * options: Ensure that an overly long bitflag string does not crash * options: Don't assume vsio options have an argument * common: Cast via uintptr_t rather than unsigned long in UNCONST * privsep: Ensure we recv for real after a successful recv MSG_PEEK * DHCP: Add parentheses to macro definitions * ipv6nd: empty IPV6RA_EXPIRE eloop queue when dropping * privsep: enforce message boundaries with MSG_EOR on our messages * Protocols will notify when dhcpcd can exit * DHCP: Don't request T1 and T2 * DHCP: Don't request a lease time * DHCP6: Don't exit if using DHCP4 INFORM in non manager mode * ND: Route Information Option prefix is optional * ipv6: respect slaac hwaddr to really use the hwaddr * When stopping all interfaces at exit and releasing, remove persistance * NetBSD: Delete RTF_CONNECTED route when changing it * privsep: Drain the log when the root process is exiting * eloop: vastly reworked, kqueue and epoll support on by default ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1147=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1147=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dhcpcd-debugsource-10.3.2-160000.1.2 * dhcpcd-debuginfo-10.3.2-160000.1.2 * dhcpcd-10.3.2-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dhcpcd-debugsource-10.3.2-160000.1.2 * dhcpcd-debuginfo-10.3.2-160000.1.2 * dhcpcd-10.3.2-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2025-70102.html * https://bugzilla.suse.com/show_bug.cgi?id=1268761 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:35:29 -0000 Subject: SUSE-SU-2026:22559-1: important: Security update for perl-List-SomeUtils-XS Message-ID: <178404692916.143.12982390840194608976@178315a69387> # Security update for perl-List-SomeUtils-XS Announcement ID: SUSE-SU-2026:22559-1 Release Date: 2026-07-06T20:10:17Z Rating: important References: * bsc#1269210 Cross-References: * CVE-2026-12844 CVSS scores: * CVE-2026-12844 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-12844 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12844 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-List-SomeUtils-XS fixes the following issue * CVE-2026-12844: heap buffer overflow in the `pairwise` function (bsc#1269210). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1144=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1144=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-List-SomeUtils-XS-debuginfo-0.58-160000.3.2 * perl-List-SomeUtils-XS-debugsource-0.58-160000.3.2 * perl-List-SomeUtils-XS-0.58-160000.3.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-List-SomeUtils-XS-debuginfo-0.58-160000.3.2 * perl-List-SomeUtils-XS-debugsource-0.58-160000.3.2 * perl-List-SomeUtils-XS-0.58-160000.3.2 ## References: * https://www.suse.com/security/cve/CVE-2026-12844.html * https://bugzilla.suse.com/show_bug.cgi?id=1269210 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:35:47 -0000 Subject: SUSE-SU-2026:22558-1: important: Security update for google-osconfig-agent Message-ID: <178404694743.143.1266040608288786281@178315a69387> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:22558-1 Release Date: 2026-07-06T20:10:17Z Rating: important References: * bsc#1210938 * bsc#1251453 * bsc#1251704 * bsc#1260264 * bsc#1262926 * bsc#1264923 * bsc#1265762 * bsc#1266171 * bsc#1266603 Cross-References: * CVE-2023-45288 * CVE-2025-22868 * CVE-2025-47911 * CVE-2025-58190 * CVE-2026-33186 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2023-45288 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2023-45288 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2023-45288 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-22868 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22868 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-41506 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-41506 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues * CVE-2023-45288: golang.org/x/net/http2: close connections when receiving too many headers. * CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251453). * CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by `html.ParseFragment` when processing specially crafted input (bsc#1251704). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265762). * CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262926). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266603). * CVE-2026-39827: Invoking memory leak when rejecting channels can lead to DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39828: Invoking bypass of certificate restrictions in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39829: Invoking pathological RSA/DSA parameters may cause DoS in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39830: Invoking client can cause server deadlock on unexpected responses in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39831: Invoking bypass of FIDO/U2F security keys physical interaction in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39832: Invoking agent constraints dropped when forwarding keys in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39833: Invoking key constraints not enforced in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-39834: Invoking infinite loop on large channel writes in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-39835: Invoking server panic during CheckHostKey/Authenticate in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-42508: Invoking auth bypass via unenforced @revoked status in golang.org/x/crypto/ssh/knownhosts (bsc#1266171). * CVE-2026-46595: Invoking VerifiedPublicKeyCallback permissions skip enforcement in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46597: Invoking byte arithmetic causes underflow and panic in golang.org/x/crypto/ssh (bsc#1266171). * CVE-2026-46598: Invoking pathological inputs can lead to client panic in golang.org/x/crypto/ssh/agent (bsc#1266171). * CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264923). Changes for google-osconfig-agent: * Update to version 20260615.01 * Upgrade golang.org/x/crypto & golang.org/x/net (#1006) * from version 20260615.00 * Add unit tests for ospatch_apt_upgrade.go (#938) * Update to version 20260611.00 * Add unit tests for policies/policies.go PART 5 (#998) * from version 20260610.00 * Add unit tests for policies/policies.go PART 4 (#997) * from version 20260609.02 * squash commits (#936) * from version 20260609.01 * Add unit tests for policies/policies.go PART 3 (#996) * from version 20260609.00 * Add unit tests for policies/policies.go PART 2 (#991) * from version 20260602.01 * Align format of dates and timestamp collected across Windows packages (#973) * from version 20260602.00 * Add unit tests for config/config,go (#979) * from version 20260528.00 * Bump github.com/containerd/containerd (#990) * from version 20260521.00 * Cover agentconfig functionality by unit tests (#925) * from version 20260520.04 * Add unit tests for policies/googet.go (#961) * Bump github.com/go-git/go-git/v5 (#987) * from version 20260520.02 * Add unit tests for policies/yum.go (#952) * Add unit tests for policies/apt.go PART 3 (#951) * from version 20260520.00 * Add unit tests for policies/zypper.go (#953) * from version 20260519.00 * Add unit tests for policies/policies.go PART 1 (#949) * from version 20260513.01 * Bump github.com/go-git/go-git/v5 (#981), this also updates golang.org/x/net to v0.53.0 (bsc#1265762, CVE-2026-33814) * from version 20260513.00 * upgrade a few packages (#980) * from version 20260512.02 * Add/improve unit tests for agentendpoint/exec_task.go (#933) * from version 20260512.01 * Cover google_update.go by unit tests (#941) * from version 20260512.00 * Change zone for arm64 builds because of stockout (#978) * Update to version 20260511.00 * switch to t2a-standard-2 on ARM package build (#977) * from version 20260505.03 * Cover zypper_patch by unit tests (#958) * from version 20260505.02 * Remove unused functions DisableAutoUpdates (#970) * from version 20260505.01 * Bump go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc (#966) * from version 20260505.00 * Upgrade a few dependencies across the repo (#968) * github.com/go-git/go-git/v5 5.16.2->5.18.0 (bsc#1264923, CVE-2026-41506) * github.com/go-jose/go-jose/v4 4.1.3->4.1.4 (bsc#1262926, CVE-2026-34986) * github.com/go-viper/mapstructure/v2 2.3.0->2.4.0 * go.opentelemetry.io/otel 1.40.0->1.41.0 * go.opentelemetry.io/otel/sdk 1.39.0->1.43.0 * from version 20260504.01 * bump github.com/docker/cli to 29.2.0 (#962) * from version 20260504.00 * Bump github.com/opencontainers/selinux (#960) * Update to version 20260428.00 * Add/improve unit tests for agentendpoint/agentendpoint.go (#930) * from version 20260427.03 * Cover config/file.go by unit tests (#935) * from version 20260422.01 * Cover patch_linux.go by unit tests (#932) * from version 20260422.00 * upgrade grpc package in main package and e2e tests (#959) (bsc#1260264, CVE-2026-33186) * from version 20260417.04 * Bump OSV-Scalibr version to v0.4.3 (#956) * from version 20260417.03 * Add unit tests for updates_linux.go (#937) * from version 20260417.02 * Add zone to CreateDisk step (#955) * from version 20260417.01 * Change disk type for deb11 (#954) * from version 20260417.00 * Add unit tests for policies/apt.go PART 1 (#950) * from version 20260410.02 * Add unit tests for packages/pty_linux.go (#943) * from version 20260410.01 * fix disk type for arm workflows (#948) * from version 20260410.00 * Change machine type for arm based workflows (#946) * Update to version 20260330.00 * bump timeouts for all workflows (#940) * from version 20260326.00 * Cover exec_resource.go by unit tests (#934) * from version 20260318.00 * Integrate OSConfig agent with ReportVmInventory (#923) * from version 20260313.02 * remove cacheonly flag from yum upgrade (#924) * from version 20260313.01 * conditions python version override (#927) * from version 20260313.00 * Fix presubmits by explicitly set python version for rpm based systems (#926) * from version 20260311.00 * Bump osconfig version (#922) * from version 20260309.02 * Extend OSV scalibr extractor (#921) * from version 20260309.01 * upgrade golang.org/x/crypto and it's transitive deps (#918) * from version 20260309.00 * Add purl to pkg info (#920) * from version 20260306.00 * Add 'Type' field to PkgInfo (#919) * from version 20260303.01 * Upgrade go.opentelemetry.io/otel/sdk (#913) * from version 20260303.00 * Bump github.com/vbatts/tar-split from 0.11.5 to 0.12.2 (#908) * from version 20260302.00 * Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.7 (#906) * from version 20260126.00 * Bump go.opentelemetry.io/otel/sdk from 1.38.0 to 1.39.0 (#905) * Bump github.com/sirupsen/logrus (#894) * Update to version 20260119.00 * Bump cloud.google.com/go/storage from 1.56.0 to 1.58.0 (#899) * Update to version 20251230.00 * chore: Migrate gsutil usage to gcloud storage (#904) * from version 20251223.00 * fix e2e tests for report inventory (#903) * from version 20251222.01 * Revert "Bump cloud.google.com/go/longrunning from 0.6.3 to 0.7.0 (#882)" (#902) * from version 20251222.00 * Bump golang to the new version (#900) * from version 20251218.00 * add new CODEOWNERS (#901) * from version 20251217.00 * Bump cloud.google.com/go/longrunning from 0.6.3 to 0.7.0 (#882) * Bump the golang compiler version to 1.24.5 * Update to version 20251202.00 * Revert "Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.5 (#887)" (#893) * Update to version 20251201.00 * Revert "Bump github.com/containerd/containerd (#890)" (#892) * Update to version 20251126.00 * Bump github.com/containerd/containerd (#890) * Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.5 (#887) * Update to version 20251028.00 * Bump go.opentelemetry.io/otel/sdk/metric from 1.35.0 to 1.38.0 (#886) * Bump github.com/tidwall/pretty from 1.2.0 to 1.2.1 (#880) * from version 20251023.02 * Create multiple_os.yaml (#883) * from version 20251023.00 * Bump github.com/docker/go-connections from 0.4.0 to 0.6.0 (#877) * Add test runner for e2e tests (#876) * Update to version 20250925.00 * Bump cloud.google.com/go/auth/oauth2adapt from 0.2.7 to 0.2.8 (#870) * Bump google.golang.org/protobuf from 1.36.6 to 1.36.9 (#874) * Bump go.opentelemetry.io/otel from 1.35.0 to 1.38.0 (#872) * Bump github.com/golang/glog from 1.2.4 to 1.2.5 (#830) * Update to version 20250902.01 * Bump github.com/googleapis/enterprise-certificate-proxy (#829) * from version 20250902.00 * update github.com/go-jose/go-jose/v4 (#869) * Upgrade scalibr and other deps (#866) * from version 20250901.00 * Fix possibility of path traversal for zip and tar archival (#868) * from version 20250825.00 * set CODEOWNERS file as required by org (#863) * from version 20250819.00 * Fix/rhel10 build centos image (#860) * from version 20250814.00 * Fix/rhel10 build image (#859) * from version 20250813.00 * Fix: Add RHEL 10 support to RPM startup script (#858) * from version 20250811.00 * Remove old/sles-15-sp4-sap as image is deprecated (#857) * Update to version 20250806.00 * Fixed JSON identifier for the universe domain (#855) * from version 20250729.00 * Bump github.com/google/s2a-go from 0.1.8 to 0.1.9 (#828) * from version 20250725.02 * Update utils.go (#854) * Upgrade golang.org/x/oauth2 package to the latest. (#853) * Bump golang.org/x/time from 0.9.0 to 0.12.0 (#839) * from version 20250725.01 * Bump golang.org/x/oauth2 (#848) * Port fix for debian 11 to goo package manager. (#852) * from version 20250725.00 * Update Golang version in common.sh and skip backports repo for debian 11 (#850) * from version 20250723.01 * Add workflows to build package for el10 (#849) * from version 20250721.00 * Make OS Config agent TPC aware (#846) * from version 20250718.00 * Create workflows for new Debian 13. (#847) * Update to version 20250703.00 * Fix sles images (#844) * from version 20250702.00 * Remove rhel-sap 8-4 add rhel-sap 8-10 (#843) * from version 20250701.00 * Bump the go_modules group across 1 directory with 2 updates (#840) * Update to version 20250606.00 * Change base docker images Google's official base images. (#838) * Update to version 20250523.01 * Add a simple no-op OS policy for user testing (#837) * from version 20250523.00 * Introduce scalibr inventory extractor for dpkg/rpm/cos os/filesystem extractors (linux) (#834) * Trace GetInstalledPackages memory levels (#835) * from version 20250520.00 * Update to version 20250513.00 * Fix rpm extractor, handle (none) value correctly. (#833) * from version 20250512.01 * Bump github.com/envoyproxy/go-control-plane from 0.13.1 to 0.13.4 (#816) * from version 20250512.00 * Bump golang.org/x/net from 0.39.0 to 0.40.0 (#819) * from version 20250508.01 * cosmetic refactoring to osinfo package (#826) * from version 20250508.00 * Refactor /inventory with dependency injection (#825) * Add debian, ubuntu (InstalledDebPackages) snapshots (#821) * cover packages_linux.go file with tests (#824) * Add debian (10,11,12) GetPackageUpdates output snapshots (#822) * from version 20250507.00 * Add InstalledRPMPackages snapshot tests (#823) * from version 20250506.02 * Yum tests: simplify initialization of exit errors (#820) * from version 20250506.01 * Improve test coverage for gem package manager (#818) * from version 20250506.00 * after go/x/crypto update 0.32.0 -> 0.37.0 (#817) * from version 20250505.01 * Improve packages package coverage (#814) * Bump golang.org/x/net from 0.34.0 to 0.39.0 (#807) * from version 20250505.00 * Bump golang.org/x/crypto from 0.32.0 to 0.37.0 (#806) * from version 20250430.00 * Snapshot YumUpdates (GetPackageUpdates) output (#813) * from version 20250428.00 * Snapshot ZypperPatches, ZypperUpdates (GetPackageUpdates) output for sles 12, 15 testdata (#812) * from version 20250423.00 * Introduce MatchSnapshot large test results matcher function, snapshot apt- deb GetPackageUpdates (#811) * from version 20250416.02 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1136=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1136=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-osconfig-agent-20260615.01-160000.1.2 * google-osconfig-agent-debuginfo-20260615.01-160000.1.2 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-osconfig-agent-20260615.01-160000.1.2 * google-osconfig-agent-debuginfo-20260615.01-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2023-45288.html * https://www.suse.com/security/cve/CVE-2025-22868.html * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1251453 * https://bugzilla.suse.com/show_bug.cgi?id=1251704 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1262926 * https://bugzilla.suse.com/show_bug.cgi?id=1264923 * https://bugzilla.suse.com/show_bug.cgi?id=1265762 * https://bugzilla.suse.com/show_bug.cgi?id=1266171 * https://bugzilla.suse.com/show_bug.cgi?id=1266603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:35:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:35:54 -0000 Subject: SUSE-SU-2026:22557-1: important: Security update for haproxy Message-ID: <178404695436.143.6354803780767893004@178315a69387> # Security update for haproxy Announcement ID: SUSE-SU-2026:22557-1 Release Date: 2026-07-07T10:14:15Z Rating: important References: * bsc#1268557 * bsc#1268558 Cross-References: * CVE-2026-55203 * CVE-2026-55204 CVSS scores: * CVE-2026-55203 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-55203 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55203 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55203 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N * CVE-2026-55204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for haproxy fixes the following issues * Update to version 3.2.21+git0.dbe43be37 * CVE-2026-55203: integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers (bsc#1268557). * CVE-2026-55204: null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c (bsc#1268558). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1166=1 ## Package List: * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * haproxy-debuginfo-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-3.2.21+git0.dbe43be37-160000.1.1 * haproxy-debugsource-3.2.21+git0.dbe43be37-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55203.html * https://www.suse.com/security/cve/CVE-2026-55204.html * https://bugzilla.suse.com/show_bug.cgi?id=1268557 * https://bugzilla.suse.com/show_bug.cgi?id=1268558 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:36:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:36:29 -0000 Subject: SUSE-SU-2026:2961-1: important: Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Message-ID: <178404698911.143.2299978595298607870@178315a69387> # Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2961-1 Release Date: 2026-07-14T10:33:59Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.163 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2961=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2961=1 ## Package List: * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-4-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-4-150500.2.2 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-4-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-4-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-4-150500.2.2 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-4-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:37:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:37:08 -0000 Subject: SUSE-SU-2026:2957-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP6) Message-ID: <178404702895.143.16245346550873924565@178315a69387> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2957-1 Release Date: 2026-07-14T10:19:59Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264094 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265127 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-31758 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43437 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.87 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2959=1 SUSE-SLE- Module-Live-Patching-15-SP6-2026-2958=1 SUSE-SLE-Module-Live- Patching-15-SP6-2026-2957=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2959=1 SUSE-2026-2958=1 SUSE-2026-2957=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_87-default-8-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-5-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-8-150600.2.2 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-8-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_87-default-8-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-5-150600.2.2 * kernel-livepatch-6_4_0-150600_23_92-default-6-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-6-150600.2.2 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-5-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-8-150600.2.2 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-8-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:37:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:37:42 -0000 Subject: SUSE-SU-2026:2956-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) Message-ID: <178404706278.143.18383478455707616549@178315a69387> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:2956-1 Release Date: 2026-07-14T10:20:15Z Rating: important References: * bsc#1260524 * bsc#1262759 * bsc#1263094 * bsc#1263118 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-23393 * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31570 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-23393 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23393 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23393 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:H/SI:N/SA:N * CVE-2026-31570 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31570 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.45 fixes various security issues The following security issues were fixed: * CVE-2026-23393: bridge: cfm: Fix race condition in peer_mep deletion (bsc#1260524). * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31570: can: gw: fix OOB heap access in cgw_csum_crc8_rel() (bsc#1263118). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-2956=1 SUSE-SLE- Module-Live-Patching-15-SP7-2026-2960=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_45-default-4-150700.2.2 * kernel-livepatch-6_4_0-150700_53_37-default-debuginfo-6-150700.2.2 * kernel-livepatch-6_4_0-150700_53_37-default-6-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_11-debugsource-6-150700.2.2 * kernel-livepatch-6_4_0-150700_53_45-default-debuginfo-4-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_13-debugsource-4-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23393.html * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31570.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1260524 * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263118 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:37:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:37:56 -0000 Subject: SUSE-SU-2026:2955-1: important: Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5) Message-ID: <178404707642.143.10740699710243654191@178315a69387> # Security update for the Linux Kernel (Live Patch 76 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2955-1 Release Date: 2026-07-14T11:34:07Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.290 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2955=1 SUSE-SLE-Live- Patching-12-SP5-2026-2973=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_290-default-10-2.1 * kgraft-patch-4_12_14-122_269-default-15-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:38:12 -0000 Subject: SUSE-SU-2026:2977-1: important: Security update for afterburn Message-ID: <178404709234.143.2203617015439620790@178315a69387> # Security update for afterburn Announcement ID: SUSE-SU-2026:2977-1 Release Date: 2026-07-14T11:44:35Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2977=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2977=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:38:30 -0000 Subject: SUSE-SU-2026:2976-1: important: Security update for afterburn Message-ID: <178404711066.143.15617849967293539095@178315a69387> # Security update for afterburn Announcement ID: SUSE-SU-2026:2976-1 Release Date: 2026-07-14T11:39:57Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2976=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2976=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * afterburn-debuginfo-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-5.10.0.git73.b97f772-150400.3.6.1 * afterburn-debugsource-5.10.0.git73.b97f772-150400.3.6.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:38:46 -0000 Subject: SUSE-SU-2026:2975-1: important: Security update for afterburn Message-ID: <178404712625.143.12583020792799238163@178315a69387> # Security update for afterburn Announcement ID: SUSE-SU-2026:2975-1 Release Date: 2026-07-14T11:38:45Z Rating: important References: * bsc#1270175 * bsc#1270483 * bsc#1270555 * bsc#1270651 * bsc#1270787 * bsc#1270817 * bsc#1270886 * bsc#1270949 * bsc#1271348 Cross-References: * CVE-2026-25541 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for afterburn fixes the following issues: Update to version 5.10.0.git73.b97f772. Security issues fixed: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270175). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270555). * CVE-2026-41678: openssl: incorrect bounds assertion in `aes::unwrap_key()` can lead to OOB write (bsc#1270651). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270787). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to network peers (bsc#1270817). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270483). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270886). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270949). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1271348). Other updates and bugfixes: * Version 5.10.0.git73.b97f772: * build(deps): bump anyhow from 1.0.99 to 1.0.103 https://github.com/coreos/afterburn/pull/1284 * build(deps): bump libflate from 2.1.0 to 2.2.2 https://github.com/coreos/afterburn/pull/1283 * build(deps): bump openssl from 0.10.79 to 0.10.80 https://github.com/coreos/afterburn/pull/1277 * Version 5.10.0.git70.9cc2a7b: * build(deps): bump openssl from 0.10.78 to 0.10.79 * providers/hetzner: Add the HETZNER_PUBLIC_IPV6 attribute * providers/hetzner: Add support for network configuration * build(deps): bump rustls-webpki from 0.103.10 to 0.103.13 * build(deps): bump openssl from 0.10.73 to 0.10.78 * docs: Add AGENTS.md and CLAUDE.md for AI coding assistants * build(deps): bump rand from 0.9.2 to 0.9.4 * opencode: add skills for provider scaffolding and release automation * ibmcloud-classic: Add missing network_id to fixture * kubevirt: Support static gateway and DNS with DHCP * build(deps): bump rustls-webpki from 0.103.6 to 0.103.10 * fix(proxmoxve): Define DNS entries for every interface * Makefile: download `90-afterburn-authorized-keys-file.conf` for rpm building * Sync repo templates ? * build(deps): bump bytes from 1.10.1 to 1.11.1 * util/dhcp: Fix clippy lints * build(deps): bump actions/checkout from 4 to 6 * build(deps): bump actions/upload-artifact from 4 to 5 * kubevirt: modprobe for virtio_blk; remove dracut preload * kubevirt: Add NoCloud network configuration support * kubevirt: Support config drive network data * kubevirt: Refactor the provider to follow the proxmoxve structure * dracut: Add virtio_blk module preload to afterburn-network-kargs service * docs: Add release notes * cargo: Afterburn release 5.10.0 * Version 5.10.0: * docs/release-notes: update for release 5.10.0 * cargo: update dependencies * microsoft/azure: Add XML attribute alias for serde-xml-rs Fedora compat * docs/release-notes: Add entry for Azure SharedConfig XML parsing fix * microsoft/azure: Fix SharedConfig parsing of XML attributes * microsoft/azure: Mock goalstate.SharedConfig output in tests * providers/azure: switch SSH key retrieval from certs endpoint to IMDS * build(deps): bump the build group with 8 updates * build(deps): bump slab from 0.4.10 to 0.4.11 * build(deps): bump actions/checkout from 4 to 5 * upcloud: implement UpCloud provider * build(deps): bump the build group with 4 updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2975=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (noarch) * afterburn-dracut-5.10.0.git73.b97f772-150500.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64) * afterburn-debugsource-5.10.0.git73.b97f772-150500.3.6.1 * afterburn-debuginfo-5.10.0.git73.b97f772-150500.3.6.1 * afterburn-5.10.0.git73.b97f772-150500.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270175 * https://bugzilla.suse.com/show_bug.cgi?id=1270483 * https://bugzilla.suse.com/show_bug.cgi?id=1270555 * https://bugzilla.suse.com/show_bug.cgi?id=1270651 * https://bugzilla.suse.com/show_bug.cgi?id=1270787 * https://bugzilla.suse.com/show_bug.cgi?id=1270817 * https://bugzilla.suse.com/show_bug.cgi?id=1270886 * https://bugzilla.suse.com/show_bug.cgi?id=1270949 * https://bugzilla.suse.com/show_bug.cgi?id=1271348 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:38:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:38:53 -0000 Subject: SUSE-SU-2026:2974-1: important: Security update for dnsmasq Message-ID: <178404713311.143.5028762807189390453@178315a69387> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:2974-1 Release Date: 2026-07-14T11:36:52Z Rating: important References: * bsc#1268764 * bsc#1268882 Cross-References: * CVE-2026-12725 * CVE-2026-12969 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues: * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). Changes for dnsmasq: * Update to 2.93: * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2974=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2974=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-2.93-18.32.1 * dnsmasq-debuginfo-2.93-18.32.1 * dnsmasq-debugsource-2.93-18.32.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * dnsmasq-2.93-18.32.1 * dnsmasq-debuginfo-2.93-18.32.1 * dnsmasq-debugsource-2.93-18.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 * https://bugzilla.suse.com/show_bug.cgi?id=1268882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:39:11 -0000 Subject: SUSE-SU-2026:2970-1: important: Security update for pacemaker Message-ID: <178404715106.143.3400799774204013356@178315a69387> # Security update for pacemaker Announcement ID: SUSE-SU-2026:2970-1 Release Date: 2026-07-14T11:27:53Z Rating: important References: * bsc#1268381 Cross-References: * CVE-2026-10649 CVSS scores: * CVE-2026-10649 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-10649 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 12 SP5 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for pacemaker fixes the following issues: * CVE-2026-10649: Fixed denial of service via integer overflow in remote message decompression (bsc#1268381). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2970=1 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2026-2970=1 * SUSE Linux Enterprise High Availability Extension 12 SP5 zypper in -t patch SUSE-SLE-HA-12-SP5-2026-2970=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2970=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64) * pacemaker-cts-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debugsource-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cts-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * SUSE Linux Enterprise High Availability Extension 12 SP5 (ppc64le s390x x86_64) * pacemaker-cts-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-remote-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debugsource-1.1.24+20210811.f5abda0ee-3.52.1 * libpacemaker3-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cts-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-1.1.24+20210811.f5abda0ee-3.52.1 * pacemaker-cli-debuginfo-1.1.24+20210811.f5abda0ee-3.52.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpacemaker-devel-1.1.24+20210811.f5abda0ee-3.52.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpacemaker-devel-1.1.24+20210811.f5abda0ee-3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10649.html * https://bugzilla.suse.com/show_bug.cgi?id=1268381 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:39:36 -0000 Subject: SUSE-SU-2026:2969-1: moderate: Security update for wireshark Message-ID: <178404717615.143.5111908100118215861@178315a69387> # Security update for wireshark Announcement ID: SUSE-SU-2026:2969-1 Release Date: 2026-07-14T11:23:14Z Rating: moderate References: * bsc#1263725 * bsc#1263728 * bsc#1263731 * bsc#1263734 * bsc#1263739 * bsc#1263743 * bsc#1263744 * bsc#1263750 * bsc#1263752 * bsc#1263753 * bsc#1263754 * bsc#1263756 * bsc#1263758 * bsc#1263765 * bsc#1263766 Cross-References: * CVE-2026-5401 * CVE-2026-5403 * CVE-2026-5404 * CVE-2026-5406 * CVE-2026-5407 * CVE-2026-5408 * CVE-2026-5653 * CVE-2026-6521 * CVE-2026-6522 * CVE-2026-6527 * CVE-2026-6532 * CVE-2026-6535 * CVE-2026-6538 * CVE-2026-6870 * CVE-2026-7379 CVSS scores: * CVE-2026-5401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5401 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5403 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5403 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-5404 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5404 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5404 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5406 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5407 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5408 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5408 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-5653 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6522 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6527 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6532 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6532 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6535 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6535 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6538 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6870 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-6870 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 15 vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues * CVE-2026-5401: AFP dissector crash (bsc#1263756). * CVE-2026-5403: SBC audio codec crash (bsc#1263765). * CVE-2026-5404: K12 RF5 file parser crash (bsc#1263766). * CVE-2026-5406: FC-SWILS dissector crash (bsc#1263754). * CVE-2026-5407: SMB2 dissector infinite loop (bsc#1263753). * CVE-2026-5408: BT-DHT dissector crash (bsc#1263752). * CVE-2026-5653: DCP-ETSI dissector crash (bsc#1263750). * CVE-2026-6521: OpenFlow v5 protocol dissector infinite loops (bsc#1263744). * CVE-2026-6522: RPKI-Router protocol dissector infinite loop (bsc#1263743). * CVE-2026-6527: ASN.1 PER dissector crash (bsc#1263739). * CVE-2026-6532: Kismet protocol dissector crash (bsc#1263734). * CVE-2026-6535: Dissection engine zlib decompression crash (bsc#1263731). * CVE-2026-6538: BEEP dissector crash (bsc#1263728). * CVE-2026-6870: GSM RP protocol dissector crash (bsc#1263725). * CVE-2026-7379: Sharkd utility memory leak (bsc#1263758). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2969=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libwiretap7-debuginfo-2.4.16-48.69.1 * libwsutil8-2.4.16-48.69.1 * wireshark-debuginfo-2.4.16-48.69.1 * libwsutil8-debuginfo-2.4.16-48.69.1 * wireshark-devel-2.4.16-48.69.1 * libwireshark9-debuginfo-2.4.16-48.69.1 * wireshark-gtk-debuginfo-2.4.16-48.69.1 * libwiretap7-2.4.16-48.69.1 * libwireshark9-2.4.16-48.69.1 * wireshark-debugsource-2.4.16-48.69.1 * wireshark-2.4.16-48.69.1 * libwscodecs1-2.4.16-48.69.1 * libwscodecs1-debuginfo-2.4.16-48.69.1 * wireshark-gtk-2.4.16-48.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5401.html * https://www.suse.com/security/cve/CVE-2026-5403.html * https://www.suse.com/security/cve/CVE-2026-5404.html * https://www.suse.com/security/cve/CVE-2026-5406.html * https://www.suse.com/security/cve/CVE-2026-5407.html * https://www.suse.com/security/cve/CVE-2026-5408.html * https://www.suse.com/security/cve/CVE-2026-5653.html * https://www.suse.com/security/cve/CVE-2026-6521.html * https://www.suse.com/security/cve/CVE-2026-6522.html * https://www.suse.com/security/cve/CVE-2026-6527.html * https://www.suse.com/security/cve/CVE-2026-6532.html * https://www.suse.com/security/cve/CVE-2026-6535.html * https://www.suse.com/security/cve/CVE-2026-6538.html * https://www.suse.com/security/cve/CVE-2026-6870.html * https://www.suse.com/security/cve/CVE-2026-7379.html * https://bugzilla.suse.com/show_bug.cgi?id=1263725 * https://bugzilla.suse.com/show_bug.cgi?id=1263728 * https://bugzilla.suse.com/show_bug.cgi?id=1263731 * https://bugzilla.suse.com/show_bug.cgi?id=1263734 * https://bugzilla.suse.com/show_bug.cgi?id=1263739 * https://bugzilla.suse.com/show_bug.cgi?id=1263743 * https://bugzilla.suse.com/show_bug.cgi?id=1263744 * https://bugzilla.suse.com/show_bug.cgi?id=1263750 * https://bugzilla.suse.com/show_bug.cgi?id=1263752 * https://bugzilla.suse.com/show_bug.cgi?id=1263753 * https://bugzilla.suse.com/show_bug.cgi?id=1263754 * https://bugzilla.suse.com/show_bug.cgi?id=1263756 * https://bugzilla.suse.com/show_bug.cgi?id=1263758 * https://bugzilla.suse.com/show_bug.cgi?id=1263765 * https://bugzilla.suse.com/show_bug.cgi?id=1263766 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:39:43 -0000 Subject: SUSE-SU-2026:2968-1: moderate: Security update for python-Authlib Message-ID: <178404718313.143.2397113874467956032@178315a69387> # Security update for python-Authlib Announcement ID: SUSE-SU-2026:2968-1 Release Date: 2026-07-14T11:15:55Z Rating: moderate References: * bsc#1263114 * bsc#1266665 Cross-References: * CVE-2026-41425 * CVE-2026-44681 CVSS scores: * CVE-2026-41425 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-41425 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-41425 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-44681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-Authlib fixes the following issues * CVE-2026-41425: no CSRF protection on the cache feature in `authlib.integrations.starlette_client.OAuth` (bsc#1263114). * CVE-2026-44681: unauthenticated open redirect in the `OpenIDImplicitGrant` and `OpenIDHybridGrant` authorization endpoints (bsc#1266665). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2968=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2968=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-Authlib-1.3.1-150600.3.22.1 * openSUSE Leap 15.6 (noarch) * python311-Authlib-1.3.1-150600.3.22.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41425.html * https://www.suse.com/security/cve/CVE-2026-44681.html * https://bugzilla.suse.com/show_bug.cgi?id=1263114 * https://bugzilla.suse.com/show_bug.cgi?id=1266665 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:39:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:39:58 -0000 Subject: SUSE-SU-2026:2967-1: moderate: Security update for libgnt, meson, pidgin Message-ID: <178404719843.143.15380830490397423921@178315a69387> # Security update for libgnt, meson, pidgin Announcement ID: SUSE-SU-2026:2967-1 Release Date: 2026-07-14T11:11:18Z Rating: moderate References: * bsc#1057701 * bsc#1062785 * bsc#1068818 * bsc#1125736 * bsc#1184786 * bsc#1191780 * bsc#1260058 * jsc#SLE-21105 Cross-References: * CVE-2019-25544 CVSS scores: * CVE-2019-25544 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2019-25544 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2019-25544 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2019-25544 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2019-25544 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability, contains one feature and has six security fixes can now be installed. ## Description: This update for libgnt, meson, pidgin fixes the following issues Security issue: * CVE-2019-25544: denial of service vulnerability that allows local attackers to crash the application by providing an excessively long username string during account creation (bsc#1260058). Non security issues: Changes for meson: * Update to version 0.46.0. * Require python2-devel for the testsuite (bsc#1125736) * Update to version 0.45.0: * Config-Tool based dependencies can be specified in a cross file. * Visual Studio C# compiler support. * Removed two deprecated features: * Generator outputs can preserve directory structure. * Hexadecimal string literals. * install_data()`defaults to``.}/{projectname * install_subdir() supports strip_directory. * Integer options. * New method meson.project_license(). * Rust cross-compilation. * Rust compiler-private library disambiguation. * Project templates. * Improve test setup selection. * Yielding subproject option to superproject. * Update to version 0.44.1: * Support running out-of-tree tests against a meson in PATH. * Don't add rpaths to system libraries. * Fix meson location detection from other meson tools. * Various boost, pkg-config and vala related fixes. * Update to version 0.44.0: * New features: * Added warning function. * Adds support for additional Qt5-Module keyword moc_extra_arguments. * Prefix-dependent defaults for sysconfdir, localstatedir and sharedstatedir. * An array type for user options. * LLVM dependency supports both dynamic and static linking. * Added if_found to subdir. * get_unquoted() method for the configuration data object. * Added disabler object. * Config-Tool based dependencies gained a method to get arbitrary options. * Disable tests for static llvm: we don't ship the static libs. * Add cmake(Qt5LinguistTools), libwmf-devel BuildRequires and zlib-devel- static: new dependencies for various tests. * Require python3-xml: mesonbuild/modules/qt5.py imports the xml module (bsc#1068818). * Update to version 0.43.0: * Generator learned capture: Generators can now be configured to capture the standard output. * Can index CustomTarget objects: The CustomTarget object can now be indexed like an array. The resulting object can be used as a source file for other Targets, this will create a dependency on the original CustomTarget, but will only insert the generated file corresponding to the index value of the CustomTarget's output keyword. * The cross file can now be used for overriding the result of find_program. Then issuing the command find_program('objdump') will return the version specified in the cross file. * Easier handling of supported compiler arguments. * Better support for shared libraries in non-system paths: This release adds feature parity to shared libraries that are either in non-standard system paths or shipped as part of your project. On systems that support rpath, Meson automatically adds rpath entries to built targets using manually found external libraries. * The Wrap dependency system now supports Subversion (svn). This support is rudimentary. The repository url has to point to a specific (sub)directory containing the meson.build file (typically trunk/). However, providing a revision is supported. * Don't use obsolete boost-devel for openSUSE Leap 15.0 and newer (bsc#1062785). * Update to version 0.42.1. * Tumbleweed meson 0.42.0-1.1fails for clang++ projects (bsc#1057701). * Update to version 0.42.0: * Distribution tarballs from Mercurial repositories. Creating distribution tarballs can now be made out of projects based on Mercurial. As before, this remains possible only with the Ninja backend. * Keyword argument verification. Meson will now check the keyword arguments used when calling any function and print a warning if any of the keyword arguments is not known. In the future this will become a hard error. * Add support for Genie to Vala compiler. The Vala compiler has an alternative syntax, Genie, that uses the .gs file extension. Meson now recognises and uses Genie files. * Pkgconfig support for additional cflags. The Pkgconfig module object can add arbitrary extra cflags to the Cflags value in the .pc file, using the "extra_cflags" keyword. * Base options accessible via get_option(). Base options are now accessible via the get_option() function. * Allow crate type configuration for Rust compiler. Rust targets now take an optional rust_crate_type keyword, allowing you to set the crate type of the resulting artifact. Valid crate types are dylib or cdylib for shared libraries, and rlib or staticlib for static libraries. For more, see Rust's linkage reference. * Simultaneous use of Address- and Undefined Behavior Sanitizers. Both the address- and undefined behavior sanitizers can now be used simultaneously by passing -Db_sanitize=address,undefined to Meson. * Unstable SIMD module. A new experimental module to compile code with many different SIMD instruction sets and selecting the best one at runtime. This module is unstable, meaning it's API is subject to change in later releases. It might also be removed altogether. * Import libraries for executables on Windows. The new keyword implib to executable() allows generation of an import library for the executable. * Added build_rpath keyword argument. You can specify build_rpath: '/foo/bar' in build targets and the given path will get added to the target's rpath in the build tree. It is removed during the install step. * Meson will print a warning when the user tries to add an rpath linker flag manually, e.g. via link_args to a target. This is not recommended because having multiple rpath causes them to stomp on each other. This warning will become a hard error in some future release. * Vulkan dependency module. Vulkan can now be used as native dependency. The dependency module will detect the VULKAN_SDK environment variable or otherwise try to receive the vulkan library and header via pkgconfig or from the system. * Limiting the maximum number of linker processes. With the Ninja backend it is now possible to limit the maximum number of concurrent linker processes. This is usually only needed for projects that have many large link steps that cause the system to run out of memory if they are run in parallel. This limit can be set with the new backend_max_links option. * Disable implicit include directories. By default Meson adds the current source and build directories to the header search path. On some rare occasions this is not desired. Setting the implicit_include_directories keyword argument to false these directories are not used. * Support for MPI dependency. MPI is now supported as a dependency. Because dependencies are language-specific, you must specify the requested language with the language keyword, i.e., dependency('mpi', language='c') will request the C MPI headers and libraries. See the MPI dependency for more information. * Allow excluding files or directories from install_subdir. The install_subdir command accepts the new exclude_files and exclude_directories keyword arguments that allow specified files or directories to be excluded from the installed subdirectory. * Make all Meson functionality invokable via the main executable. Previously Meson had multiple executables such as mesonintrospect and mesontest. They are now invokable via the main Meson executable like this: meson configure # equivalent to mesonconf meson test # equivalent to mesontest The old commands are still available but they are deprecated and will be removed in some future release. * Pcap dependency detector. Meson will automatically obtain dependency information for pcap using the pcap-config tool. It is used like any other dependency. * GNOME module mkenums_simple() addition. Most libraries and applications use the same standard templates for glib-mkenums. There is now a new mkenums_simple() convenience method that passes those default templates to glib-mkenums and allows some tweaks such as optional function decorators or leading underscores. * Update to version 0.41.2: * Various gtkdoc fixes. * Fix how rpath directories are handled. * pkgconfig: avoid appending slash at Cflags. * Fix a missing path issue causing Python traceback. * Qt4 support. * Skip handling non-available dependencies. * vala: Only add --use-header for unity builds regression. * Tag functions in asm properly. * Update to version 0.41.1: * wxwidgets: Fix usage of multiple dependency() calls. * Make external library no-op when used with incompatible target (gh#mesonbuild/meson#1941). * Failing test for -D dedupping. * Preserve standalone -D arguments always. * Handle both pkg-config and pkgconf argument order (gh#mesonbuild/meson#1934). * Update to version 0.41.0: * Native support for linking against LLVM using the dependency function. * Pkgconfig support for custom variables. * A target for creating tarballs using 'ninja dist'. * Support for passing arguments to Rust compiler. * All known issues regarding reproducible builds are fixed. * Extended template substitution in configure_file for @BASENAME@ and @PLAINNAME@ . * Support for capturing stdout of a command in configure_file. * Update to version 0.40.1: * Outputs of generators can be used in custom targets in the VS * Visual Studio 2017 support. * Automatic initialization of subprojects that are git submodules. * No download mode for wraps. * Overriding options per target. * Compiler object get define. * Cygwin support. * Multiple install directories. * Can specify method of obtaining dependencies. * Link whole contents of static libraries. * Unity builds only for subprojects. * Running mesonintrospect from scripts. * Update to version 0.39.1: * Allow specifying extra arguments for tests. * Bug fixes and minor polishes. * Update to version 0.38.1: * New Uninstall target. * Support for arbitrary test setups. * Intel C/C++ compiler support. * Get values from configuration data objects. * Python 3 module support simplified. * Default options to subprojects. * Set targets to be built (or not) by default. * Add option to mesonconf to wipe cached data. * Can specify file permissions and owner when installing data. * has_header() checks are now faster. * Array indexing now supports fallback values. * Silent mode for Mesontest. * Update to version 0.37.1. * Update to version 0.37.0: * Mesontest: a new testing tool that allows you to run your tests in many different ways. * New shared_module function allows shared modules creation. * GNOME module now detects required programs and prints useful errors if any are missing. * GNOME module uses depfile support available in GLib >= 2.52.0. * i18n module has a new merge_file() function for creating translated files. * LLVM IR compilation is now supported. * .wrap files for subprojects can now include a separate push URL to allow developers to push changes directly from a subproject git checkout. * Multiple version restrictions while searching for pkg-config dependencies is now supported. * Support for localstatedir has been added. * You can now pass arguments to install scripts added with meson.add_install_script(). * Added new options sbindir and infodir that can be used for installation. * Update to version 0.36.0: * Add option to run under gdb. * Always specify installed data with a File object (gh#mesonbuild/meson#858). * Made has_function survive optimization flags (gh#mesonbuild/meson#1053). * Can give many alternative names to find_program to simplify searching. * Can set compiler arguments in Java. * Changes from version 0.34.0: * Correctly install .typelib files to libdir. * Add option for as-needed link option. * Print the CFLAGS/LDFLAGS/etc inherited from the environment. * Only append compile flags to the link flags when appropriate. * Update to version 0.32.0. * Update to version 0.31.0. * Update to 0.29.0. * Update to 0.28.0. * Update to 0.27.0. * Update to 0.26.0. Changes for libgnt: * update to 2.14.3: * Added an option to disable python2 support. * Add an option to disable building the docs. * Fix a SEGFAULT in gnt_combo_box_get_dropdown. * Fix an invalid read/write when hiding widgets * Look for python-2.7.pc as well as python2.pc * Bump the minimum meson version from 0.37.0 to 0.41.0 * Fix a buffer size in gntwm.c Changes for pidgin: * Update to version 2.14.8: * Fix a regression in purple_str_to_time * Update to version 2.14.7: * Fix leak in purple_markup_find_tag on error * Fix an assert in purple_markup_html_to_xhtml * Correctly free parse tags at end of purple_html_to_xhtml * Fix leak that may occur when xmlnode_from_str fails * Port purple_str_to_time to use a regular expressions * Update to version 2.14.6: * Update references to point to our current websites. * Add a donate link to the help menu. Finch: * Check pkg-config for ncurses before looking for it manually. Pidgin: * Replace newlines in topics with spaces. libpurple: * Added support for the no_proxy environment variable. * Added infrastructure for fuzzing as well as some initial fuzzers. * Fix an out of bounds write in purple_markup_linkify. XMPP: * Enable session management after binding a resource. Zephyr: * Fix a clang logical-not-parentheses warning. * Update to version 2.14.5: * static code analysis fixes * Disable UPnP and NAT-PMP by default for new user * IRC: Change the default server to irc.libera.chat * Update to version 2.14.4: * Use LT_LIB_M to find the math library. This should simplify things for various distros including the BSD's. (RR #608) (and, Justin Lechner) * Update purple-remote and purple-url-handler to have a Python 3 shebang. * Install our AppData file into the $prefix/share/metainfo. Windows-Specific Changes: * Output pkg-config files so that our Windows builds can be seen by meson. Grim owes a blog post on how this works. * Update the debug symbols download in the installer to the inetc plugin. * Make sure the uninstaller removes all files that we install. * Removed the AIM protocol plugin. AIM has been shut down since December 15th of 2017. We left it around because of a third party server, but our plugin no longer works with it. (RR #598) (Gary Kramlich) * Standardize on wprintf in pidgin/win32/winpidgin.c * Use the inetc nsis plugin that supports https * If building under msys2 copy libgcc_s_dw2-1.dll and libwinpthread to the install directory. (RR #593) (PIDGIN-17511) (Gary Kramlich) * Fix a build issue when compiling with gstreamer but without voice and video. * Enable cyrus-sasl by default. * Fix an issue with opening link in Firefox. * Fix a regression from 2.14.0 where extra whitespace would be displayed when pasting

elements from HTML. * Require Python 3 for generating the D-Bus bindings. * Fix an issue where pasting


's and other HTML elements would eventually lead to a crash. * Update to version 2.14.1: * Fix an issue that caused the Mercurial revision in the About box to be "unknown". * Update to version 2.14.0: General: \+ Fixed a memory leak in search results (pidgin.im#17292). \+ Support SNI with GnuTLS (pidgin.im#17300 tiagosalem). \+ Add additional error handling to NSS and GnuTLS. \+ libpurple: \+ Add invisible buddy support to support presence/name/photos for non-buddies (pidgin.im#17295). \+ Make purple-remote compatible with both Python 2 and Python 3. \+ Fix some leaky deprecation warnings. \+ Fix HTML logs which were writing invalid HTML (pidgin.im#17280). \+ Fix use after free in purple_smiley_set_data_impl. \+ Added the chat_send_file ability to protocol plugins. Pidgin: \+ Treat

tags as line breaks when pasting. \+ Reverted pidgin.im#17232. It caused more harm than good. Bonjour: \+ Always use port fallback for IPv4 addresses. \+ XMPP: \+ Support for XEP-0198 Stream Management. \+ Decrease delay for file transfer using streamhosts. \+ Voice & Video: \+ Improve webcam failure handling. \+ Show error when creating media pipeline fails. \+ Clip audio level reporting (pidgin.im#14426). \+ Keep track of devices managed by GstDeviceMonitor. \+ Ignore PulseAudio monitors. \+ Backport native Voice & Video prefs from 3.0. \+ Fix building against GStreamer 0.10. \+ Fix initial delay on incoming audio. \+ Properly cleanup timeouts. \+ Add an audio mixer so mixed sources don't cause a pipe failure. \+ Add screen share support for Wayland via XDP Portal. \+ Handle unplug and replug events of selected media device. * Update to version 2.13.0: * Unified string comparison. * Properlly shell escape URI's when opening them. * Fix a one byte buffer overread in function purple_markup_linkify. * Fix an issue were utf8 was incorrectly truncated which could lead to crashes as we were potentially feeding garbage into glib/gtk. libgnt: * Partially fix building against curses 6.0 with opaque structs set (pidgin.im#16764). * Fix a crash when resizing the window (pidgin.im#16680). * Fix a bashism in autotools (pidgin.im#16836). * Show XEP-0066 OOB URLs in any message, not just headlines. * Fix a user after free (pidgin.im#17200). * Remove pipelining from BOSH connections (pidgin.im#17025). * Don't try to TLS already secured BOSH connections (pidgin.im#17270). IRC: * Fix "Registration timeout" on SASL auth with InspIRCd servers (and possibly others not based on charybdis/ratbox/ircd-seven). * Fix issues with plugins that modify outgoing messages (such as the custom PART/QUIT feature of the IRC More plugin). * Fix IRC buffer handling (pidgin.im#12562). * Properly handle AUTHENTICATE as a normal command with server prefix. * Fix a crash caused by a use after free of the MOTD. * Fix an out of bounds read in irc_nick_skip_mode. * Fix a write of a single byte before the start of a buffer in irc_parse_ctcp. * Better support for dark themes (pidgin.im#12572). * Fix IPv6 links by not escaping []'s. (pidgin.im#16391). * Only write buddy icons to the cache if they're not already cached. * Rejoin persistent chats after reconnect (pidgin.im#15687). * Make the WIN32 Transparency plugin work on all platforms (pidgin.im#3124). * Ensure search results buttons are labelled. * Fix matching unicode emoticons (pidgin.im#17232). * Correctly update mute/unmute status when the remote side mutes/unmutes us (pidgin.im#17273). * Rework the status icon blinking to not use deprecated API (pidgin.im#17174). * Do not allow adding a buddy to protocols that don't have an add_buddy callback. * Finch: * Fix handling of search results (pidgin.im#17238). * Port backend-fs to newer api for farstream relay-info property (pidgin.im#17274). * Add purple-import-empathy Recommends for SLE15 (FATE#322984). * Remove obsolete translation-update-upstream support (jsc#SLE-21105). * Extract libpurple.so._and libpurple-client.so._ to own packages (bsc#1191780). * don't package directories owned by filesystem rpm (bsc#1184786) * Drop support for openSUSE older than Leap 15.0. * No longer recommend -lang: supplements are in use * Drop pkgconfig(NetworkManager) BuildRequires and Requires: this legacy symbol is no longer maintained and pidgin is not yet ready to move to libnm. As a side-effect, we no longer depend on NM for all situations, even if the system were to run wicked. * Replace --enable-nm configure parameter with --disable-nm. * Instead of removing the libjabber.so, liboscar.so symlinks, move them to the devel package. * Export PYTHON=python3 in %build. * Adjust scripts to invoke python3, not python2. * Drop support for SLE 11 and openSUSE older than 42.x. * Correct the licence to GPL-2.0. * Explicitly require python2 * Drop dependency over silc-toolkit-devel as we want to remove it from the distribution ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2967=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2967=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * farstream-devel-0.2.8-5.2.4 * libnice-debugsource-0.1.13-7.2.3 * libfarstream-0_2-5-0.2.8-5.2.4 * libgnt-devel-2.14.3-4.3.8 * gstreamer-plugins-farstream-0.2.8-5.2.4 * libgupnp-1_0-4-0.20.18-8.5.2 * libpurple-debuginfo-2.14.8-3.9.3 * libpurple-client0-debuginfo-2.14.8-3.9.3 * libnice-devel-0.1.13-7.2.3 * libgupnp-devel-0.20.18-8.5.2 * libpurple-tcl-debuginfo-2.14.8-3.9.3 * libgnt-debugsource-2.14.3-4.3.8 * gssdp-debugsource-0.14.16-7.2.1 * finch-devel-2.14.8-3.9.3 * libnice-debuginfo-0.1.13-7.2.3 * libgupnp-igd-devel-0.2.4-6.2.2 * libgssdp-1_0-3-debuginfo-0.14.16-7.2.1 * farstream-debugsource-0.2.8-5.2.4 * typelib-1_0-Farstream-0_2-0.2.8-5.2.4 * libgupnp-1_0-4-debuginfo-0.20.18-8.5.2 * finch-debuginfo-2.14.8-3.9.3 * libpurple0-2.14.8-3.9.3 * finch-2.14.8-3.9.3 * gupnp-debugsource-0.20.18-8.5.2 * libpurple-client0-2.14.8-3.9.3 * typelib-1_0-GUPnPIgd-1_0-0.2.4-6.2.2 * libpurple-2.14.8-3.9.3 * libpurple-tcl-2.14.8-3.9.3 * libnice10-0.1.13-7.2.3 * libgnt0-2.14.3-4.3.8 * libgnt-devel-debuginfo-2.14.3-4.3.8 * libpurple-devel-2.14.8-3.9.3 * libgssdp-1_0-3-0.14.16-7.2.1 * typelib-1_0-GUPnP-1_0-0.20.18-8.5.2 * libgnt0-debuginfo-2.14.3-4.3.8 * libgssdp-devel-0.14.16-7.2.1 * libpurple0-debuginfo-2.14.8-3.9.3 * typelib-1_0-GSSDP-1_0-0.14.16-7.2.1 * libgupnp-igd-1_0-4-0.2.4-6.2.2 * libfarstream-0_2-5-debuginfo-0.2.8-5.2.4 * libgupnp-igd-1_0-4-debuginfo-0.2.4-6.2.2 * libnice10-debuginfo-0.1.13-7.2.3 * pidgin-devel-2.14.8-3.9.3 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * libpurple-lang-2.14.8-3.9.3 * libpurple-branding-upstream-2.14.8-3.9.3 * farstream-data-0.2.8-5.2.4 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libgnt0-32bit-2.14.3-4.3.8 * libgnt0-debuginfo-32bit-2.14.3-4.3.8 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * farstream-devel-0.2.8-5.2.4 * libnice-debugsource-0.1.13-7.2.3 * libfarstream-0_2-5-0.2.8-5.2.4 * libpurple-debuginfo-2.14.8-3.9.3 * gstreamer-plugins-farstream-0.2.8-5.2.4 * libgupnp-1_0-4-0.20.18-8.5.2 * libgnt-devel-2.14.3-4.3.8 * libpurple-client0-debuginfo-2.14.8-3.9.3 * libnice-devel-0.1.13-7.2.3 * libgupnp-devel-0.20.18-8.5.2 * libpurple-tcl-debuginfo-2.14.8-3.9.3 * libgnt-debugsource-2.14.3-4.3.8 * gssdp-debugsource-0.14.16-7.2.1 * finch-devel-2.14.8-3.9.3 * libnice-debuginfo-0.1.13-7.2.3 * libgupnp-igd-devel-0.2.4-6.2.2 * libgssdp-1_0-3-debuginfo-0.14.16-7.2.1 * farstream-debugsource-0.2.8-5.2.4 * typelib-1_0-Farstream-0_2-0.2.8-5.2.4 * libgupnp-1_0-4-debuginfo-0.20.18-8.5.2 * finch-debuginfo-2.14.8-3.9.3 * libpurple0-2.14.8-3.9.3 * finch-2.14.8-3.9.3 * gupnp-debugsource-0.20.18-8.5.2 * libpurple-client0-2.14.8-3.9.3 * typelib-1_0-GUPnPIgd-1_0-0.2.4-6.2.2 * libpurple-tcl-2.14.8-3.9.3 * libpurple-2.14.8-3.9.3 * libnice10-0.1.13-7.2.3 * libgnt0-2.14.3-4.3.8 * libgnt-devel-debuginfo-2.14.3-4.3.8 * libpurple-devel-2.14.8-3.9.3 * libgssdp-1_0-3-0.14.16-7.2.1 * typelib-1_0-GUPnP-1_0-0.20.18-8.5.2 * libgssdp-devel-0.14.16-7.2.1 * libpurple0-debuginfo-2.14.8-3.9.3 * libgnt0-debuginfo-2.14.3-4.3.8 * typelib-1_0-GSSDP-1_0-0.14.16-7.2.1 * libgupnp-igd-1_0-4-0.2.4-6.2.2 * libfarstream-0_2-5-debuginfo-0.2.8-5.2.4 * libgnt0-32bit-2.14.3-4.3.8 * libgupnp-igd-1_0-4-debuginfo-0.2.4-6.2.2 * libnice10-debuginfo-0.1.13-7.2.3 * pidgin-devel-2.14.8-3.9.3 * libgnt0-debuginfo-32bit-2.14.3-4.3.8 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libpurple-lang-2.14.8-3.9.3 * libpurple-branding-upstream-2.14.8-3.9.3 * farstream-data-0.2.8-5.2.4 ## References: * https://www.suse.com/security/cve/CVE-2019-25544.html * https://bugzilla.suse.com/show_bug.cgi?id=1057701 * https://bugzilla.suse.com/show_bug.cgi?id=1062785 * https://bugzilla.suse.com/show_bug.cgi?id=1068818 * https://bugzilla.suse.com/show_bug.cgi?id=1125736 * https://bugzilla.suse.com/show_bug.cgi?id=1184786 * https://bugzilla.suse.com/show_bug.cgi?id=1191780 * https://bugzilla.suse.com/show_bug.cgi?id=1260058 * https://jira.suse.com/browse/SLE-21105 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:08 -0000 Subject: SUSE-SU-2026:2965-1: important: Security update for kubernetes-old Message-ID: <178404720833.143.8904692373489169334@178315a69387> # Security update for kubernetes-old Announcement ID: SUSE-SU-2026:2965-1 Release Date: 2026-07-14T11:10:09Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for kubernetes-old rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-2965=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2965=1 ## Package List: * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kubernetes1.33-client-1.33.11-150600.13.34.1 * kubernetes1.33-client-common-1.33.11-150600.13.34.1 * Containers Module 15-SP7 (noarch) * kubernetes1.33-client-bash-completion-1.33.11-150600.13.34.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * kubernetes1.33-client-1.33.11-150600.13.34.1 * kubernetes1.33-client-common-1.33.11-150600.13.34.1 * openSUSE Leap 15.6 (noarch) * kubernetes1.33-client-fish-completion-1.33.11-150600.13.34.1 * kubernetes1.33-client-bash-completion-1.33.11-150600.13.34.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:12 -0000 Subject: SUSE-SU-2026:2964-1: important: Security update for buildah Message-ID: <178404721248.143.15062380998925085936@178315a69387> # Security update for buildah Announcement ID: SUSE-SU-2026:2964-1 Release Date: 2026-07-14T11:09:44Z Rating: important References: Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that can now be installed. ## Description: This update for buildah rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2964=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2964=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2964=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2964=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2964=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150400.3.70.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * buildah-1.35.5-150400.3.70.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:18 -0000 Subject: SUSE-SU-2026:2963-1: moderate: Security update for ucode-intel Message-ID: <178404721849.143.4641286785737350528@178315a69387> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:2963-1 Release Date: 2026-07-14T11:08:50Z Rating: moderate References: * bsc#1265189 Cross-References: * CVE-2025-35979 CVSS scores: * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for ucode-intel fixes the following issue: * CVE-2025-35979: data leaks fixed in 20260512 release (bsc#1265189). Other changes: * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189). **New Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products PTL 404 A1 06-cc-03/90 0000011b Intel Core Ultra Processor (Series 3) PTL-H 484/12Xe A0/B0 06-cc-02/90 0000011b Intel Core Ultra Processor (Series 3) **Updated Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products ARL-H A1 06-c5-02/82 0000011b 00000121 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 0000011b 00000121 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002d3 210002e0 Xeon Scalable Gen5 GNR-AP/SP Bx/Hx/Lx 06-ad-01/95 01000405 01000423 Xeon 6900/6700/6500 Series Processors with P-Cores GNR-D B0/B1 06-ae-01/97 01000303 01000307 Xeon 6700P-B/6500P-B Series SoC with P-Cores GNR-SP R1S Bx/Hx/Lx 06-ad-01/20 0a000133 0a000142 Xeon 6700/6500-Series Processors with P-Cores LNL B0 06-bd-01/80 00000125 00000126 Core Ultra 200 V Series Processor SPR-SP E4/S2 06-8f-07/87 2b000661 2b000670 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000661 2b000670 Xeon Scalable Gen4 SRF-AP/SP C0 06-af-03/01 03000382 030003a3 Xeon 6900/6700-Series Processors with E-Cores ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2963=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2963=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2963=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2963=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2963=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2963=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2963=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2963=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2963=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2963=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2963=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2963=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2963=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2963=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2963=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2963=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260512-150200.65.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260512-150200.65.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260512-150200.65.1 ## References: * https://www.suse.com/security/cve/CVE-2025-35979.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:23 -0000 Subject: SUSE-SU-2026:2962-1: moderate: Security update for perl-libwww-perl Message-ID: <178404722392.143.7551874890507893160@178315a69387> # Security update for perl-libwww-perl Announcement ID: SUSE-SU-2026:2962-1 Release Date: 2026-07-14T10:55:03Z Rating: moderate References: * bsc#1265156 Cross-References: * CVE-2026-8368 CVSS scores: * CVE-2026-8368 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-8368 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-libwww-perl fixes the following issue * CVE-2026-8368: LWP: UserAgent: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects (bsc#1265156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2962=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * perl-libwww-perl-6.31-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8368.html * https://bugzilla.suse.com/show_bug.cgi?id=1265156 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:29 -0000 Subject: SUSE-SU-2026:2954-1: important: Security update for krb5 Message-ID: <178404722926.143.4045934093773535494@178315a69387> # Security update for krb5 Announcement ID: SUSE-SU-2026:2954-1 Release Date: 2026-07-14T09:57:42Z Rating: important References: * bsc#1268131 Cross-References: * CVE-2026-11850 CVSS scores: * CVE-2026-11850 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-11850 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for krb5 fixes the following issue * CVE-2026-11850: integer underflow in berval2tl_data() leads to heap out-of- bounds read (bsc#1268131). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2954=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2954=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2954=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2954=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2954=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2954=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2954=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2954=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2954=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-mini-debugsource-1.19.2-150400.3.24.1 * krb5-plugin-preauth-spake-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-mini-debuginfo-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-mini-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-mini-devel-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-plugin-preauth-spake-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * openSUSE Leap 15.4 (aarch64_ilp32) * krb5-64bit-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-64bit-1.19.2-150400.3.24.1 * krb5-64bit-1.19.2-150400.3.24.1 * openSUSE Leap 15.4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-32bit-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * krb5-client-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-pkinit-1.19.2-150400.3.24.1 * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-server-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-client-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * krb5-devel-1.19.2-150400.3.24.1 * krb5-server-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-debuginfo-1.19.2-150400.3.24.1 * krb5-plugin-preauth-otp-1.19.2-150400.3.24.1 * krb5-plugin-kdb-ldap-1.19.2-150400.3.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * krb5-32bit-debuginfo-1.19.2-150400.3.24.1 * krb5-32bit-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * krb5-debugsource-1.19.2-150400.3.24.1 * krb5-1.19.2-150400.3.24.1 * krb5-debuginfo-1.19.2-150400.3.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11850.html * https://bugzilla.suse.com/show_bug.cgi?id=1268131 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:52 -0000 Subject: SUSE-SU-2026:2950-1: moderate: Security update for perl-HTML-Parser Message-ID: <178404725206.143.16404115424664021610@178315a69387> # Security update for perl-HTML-Parser Announcement ID: SUSE-SU-2026:2950-1 Release Date: 2026-07-14T09:24:36Z Rating: moderate References: * bsc#1267606 Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-8829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTML-Parser fixes the following issue * CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2950=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * perl-HTML-Parser-debugsource-3.830.0-150000.3.6.1 * perl-HTML-Parser-debuginfo-3.830.0-150000.3.6.1 * perl-HTML-Parser-3.830.0-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html * https://bugzilla.suse.com/show_bug.cgi?id=1267606 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:40:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:40:57 -0000 Subject: SUSE-SU-2026:2949-1: moderate: Security update for python-mistune Message-ID: <178404725763.143.4609619052121562364@178315a69387> # Security update for python-mistune Announcement ID: SUSE-SU-2026:2949-1 Release Date: 2026-07-14T09:23:51Z Rating: moderate References: * bsc#1265052 Cross-References: * CVE-2026-44898 CVSS scores: * CVE-2026-44898 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-44898 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44898 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-mistune fixes the following issue * CVE-2026-44898: improper sanitization of user-supplied HTML input in `render_toc_ul` can lead to XSS (bsc#1265052). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-2949=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2949=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-mistune-2.0.5-150400.11.8.1 * openSUSE Leap 15.4 (noarch) * python311-mistune-2.0.5-150400.11.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44898.html * https://bugzilla.suse.com/show_bug.cgi?id=1265052 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 16:41:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 16:41:03 -0000 Subject: SUSE-SU-2026:2948-1: moderate: Security update for perl-HTML-Parser Message-ID: <178404726338.143.5404591927834998940@178315a69387> # Security update for perl-HTML-Parser Announcement ID: SUSE-SU-2026:2948-1 Release Date: 2026-07-14T09:23:13Z Rating: moderate References: * bsc#1267606 Cross-References: * CVE-2026-8829 CVSS scores: * CVE-2026-8829 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-8829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-HTML-Parser fixes the following issue * CVE-2026-8829: HTML:Entities versions before 3.84 for Perl read freed heap memory in _decode_entities (bsc#1267606). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2948=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-HTML-Parser-3.71-3.3.1 * perl-HTML-Parser-debuginfo-3.71-3.3.1 * perl-HTML-Parser-debugsource-3.71-3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8829.html * https://bugzilla.suse.com/show_bug.cgi?id=1267606 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:30:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:30:31 -0000 Subject: SUSE-SU-2026:2991-1: important: Security update for the Linux Kernel (Live Patch 54 for SUSE Linux Enterprise 15 SP4) Message-ID: <178406103160.173.2864831226820461792@178315a69387> # Security update for the Linux Kernel (Live Patch 54 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2991-1 Release Date: 2026-07-14T16:05:09Z Rating: important References: * bsc#1264094 * bsc#1265197 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-31758 * CVE-2026-43037 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.219 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2991=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2991=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_219-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_219-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-2-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:30:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:30:57 -0000 Subject: SUSE-SU-2026:2989-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Message-ID: <178406105782.173.3430621592195986198@178315a69387> # Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:2989-1 Release Date: 2026-07-14T15:46:16Z Rating: important References: * bsc#1264094 * bsc#1265117 * bsc#1265197 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-31758 * CVE-2026-43037 * CVE-2026-43366 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.166 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-2989=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-2989=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_166-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-2-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_166-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-2-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:31:13 -0000 Subject: SUSE-SU-2026:2992-1: important: Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5) Message-ID: <178406107385.173.10607396600705455531@178315a69387> # Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2992-1 Release Date: 2026-07-14T16:05:27Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.293 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2992=1 SUSE-SLE-Live- Patching-12-SP5-2026-2985=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_266-default-18-2.1 * kgraft-patch-4_12_14-122_293-default-9-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:31:24 -0000 Subject: SUSE-SU-2026:2987-1: moderate: Security update for glibc Message-ID: <178406108464.173.9605202494795084566@178315a69387> # Security update for glibc Announcement ID: SUSE-SU-2026:2987-1 Release Date: 2026-07-14T14:37:38Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues: * CVE-2026-5435: resolv: More types as unknown in ns_sprintrrf (bsc#1263656, BZ #34033) * resolv: Check for inet_ntop failure in ns_sprintrrf * CVE-2026-6238: resolv: Fix buffer overreads in ns_sprintrrf (bsc#1263658, BZ #34069) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2987=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * glibc-devel-static-2.22-114.49.1 * glibc-profile-2.22-114.49.1 * nscd-2.22-114.49.1 * glibc-locale-debuginfo-2.22-114.49.1 * nscd-debuginfo-2.22-114.49.1 * glibc-profile-32bit-2.22-114.49.1 * glibc-devel-debuginfo-2.22-114.49.1 * glibc-locale-debuginfo-32bit-2.22-114.49.1 * glibc-debuginfo-32bit-2.22-114.49.1 * glibc-devel-debuginfo-32bit-2.22-114.49.1 * glibc-2.22-114.49.1 * glibc-devel-2.22-114.49.1 * glibc-debugsource-2.22-114.49.1 * glibc-devel-32bit-2.22-114.49.1 * glibc-locale-2.22-114.49.1 * glibc-locale-32bit-2.22-114.49.1 * glibc-32bit-2.22-114.49.1 * glibc-debuginfo-2.22-114.49.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * glibc-info-2.22-114.49.1 * glibc-i18ndata-2.22-114.49.1 * glibc-html-2.22-114.49.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:31:34 -0000 Subject: SUSE-SU-2026:2984-1: moderate: Security update for python3-dulwich Message-ID: <178406109484.173.53504495862507263@178315a69387> # Security update for python3-dulwich Announcement ID: SUSE-SU-2026:2984-1 Release Date: 2026-07-14T13:21:03Z Rating: moderate References: * bsc#1268138 Cross-References: * CVE-2026-47734 CVSS scores: * CVE-2026-47734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47734 ( NVD ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python3-dulwich fixes the following issues: * CVE-2026-47734: Do not honour receive.maxInputSize to bound received packs (bsc#1268138) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2984=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2984=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-dulwich-debugsource-0.20.24-150400.8.1 * python3-dulwich-debuginfo-0.20.24-150400.8.1 * python3-dulwich-0.20.24-150400.8.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python3-dulwich-debugsource-0.20.24-150400.8.1 * python3-dulwich-debuginfo-0.20.24-150400.8.1 * python3-dulwich-0.20.24-150400.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47734.html * https://bugzilla.suse.com/show_bug.cgi?id=1268138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:31:46 -0000 Subject: SUSE-SU-2026:2983-1: moderate: Security update for jq Message-ID: <178406110668.173.17076720896941310240@178315a69387> # Security update for jq Announcement ID: SUSE-SU-2026:2983-1 Release Date: 2026-07-14T13:19:55Z Rating: moderate References: * bsc#1262044 * bsc#1262069 * bsc#1262070 * bsc#1262071 * bsc#1262072 Cross-References: * CVE-2026-32316 * CVE-2026-33947 * CVE-2026-39956 * CVE-2026-39979 * CVE-2026-40164 CVSS scores: * CVE-2026-32316 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-32316 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32316 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-33947 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33947 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33947 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39956 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39956 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-39956 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39979 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-39979 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-39979 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-39979 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-32316: integer overflow within the `jvp_string_append()` and `jvp_string_copy_replace_bad` functions can lead to heap buffer overflow when evaluating untrusted jq queries (bsc#1262044). * CVE-2026-33947: unbounded recursion in functions `jv_setpath()`, `jv_getpath()`, and `delpaths_sorted()` can lead to excessive resource consumption when processing crafted JSON input (bsc#1262069). * CVE-2026-39956: missing runtime type checks in `_strindices` and `jv_string_indexes()` can lead to a crash when evaluating untrusted jq filters against a release build (bsc#1262070). * CVE-2026-39979: incorrect processing of non-nul-terminated counted buffers in `jv_parse_sized` can lead to an out-of-bounds read when processing malformed JSON (bsc#1262071). * CVE-2026-40164: use of `MurmurHash3` with a hardcoded seed allows pre- computation of key collisions and can lead to a denial of service via resource exhaustion when processing crafted JSON objects (bsc#1262072). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2983=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-2983=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2983=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2983=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-2983=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2983=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjq-devel-1.6-150000.3.20.1 * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * jq-1.6-150000.3.20.1 * jq-debugsource-1.6-150000.3.20.1 * libjq1-1.6-150000.3.20.1 * libjq1-debuginfo-1.6-150000.3.20.1 * jq-debuginfo-1.6-150000.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32316.html * https://www.suse.com/security/cve/CVE-2026-33947.html * https://www.suse.com/security/cve/CVE-2026-39956.html * https://www.suse.com/security/cve/CVE-2026-39979.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://bugzilla.suse.com/show_bug.cgi?id=1262044 * https://bugzilla.suse.com/show_bug.cgi?id=1262069 * https://bugzilla.suse.com/show_bug.cgi?id=1262070 * https://bugzilla.suse.com/show_bug.cgi?id=1262071 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:31:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:31:55 -0000 Subject: SUSE-SU-2026:2982-1: moderate: Security update for python-WebOb Message-ID: <178406111507.173.14994617790690046708@178315a69387> # Security update for python-WebOb Announcement ID: SUSE-SU-2026:2982-1 Release Date: 2026-07-14T13:15:39Z Rating: moderate References: * bsc#1268324 Cross-References: * CVE-2026-44889 CVSS scores: * CVE-2026-44889 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-44889 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44889 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-WebOb fixes the following issue * CVE-2026-44889: Location header normalization during redirect leads to open redirect (bsc#1268324). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-2982=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-2982=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-WebOb-1.7.4-150000.3.6.1 * SUSE Package Hub 15 15-SP7 (noarch) * python2-WebOb-1.7.4-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44889.html * https://bugzilla.suse.com/show_bug.cgi?id=1268324 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Jul 14 20:32:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 14 Jul 2026 20:32:01 -0000 Subject: SUSE-SU-2026:2981-1: moderate: Security update for ucode-intel Message-ID: <178406112103.173.16888415570155095400@178315a69387> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:2981-1 Release Date: 2026-07-14T13:13:41Z Rating: moderate References: * bsc#1265189 Cross-References: * CVE-2025-35979 CVSS scores: * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for ucode-intel fixes the following issue: * CVE-2025-35979: data leaks fixed in 20260512 release (bsc#1265189). Changes for ucode-intel: * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189). **New Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products PTL 404 A1 06-cc-03/90 0000011b Intel Core Ultra Processor (Series 3) PTL-H 484/12Xe A0/B0 06-cc-02/90 0000011b Intel Core Ultra Processor (Series 3) **Updated Platforms** Processor Stepping F-M-S/PI Old Ver New Ver Products ARL-H A1 06-c5-02/82 0000011b 00000121 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 0000011b 00000121 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002d3 210002e0 Xeon Scalable Gen5 GNR-AP/SP Bx/Hx/Lx 06-ad-01/95 01000405 01000423 Xeon 6900/6700/6500 Series Processors with P-Cores GNR-D B0/B1 06-ae-01/97 01000303 01000307 Xeon 6700P-B/6500P-B Series SoC with P-Cores GNR-SP R1S Bx/Hx/Lx 06-ad-01/20 0a000133 0a000142 Xeon 6700/6500-Series Processors with P-Cores LNL B0 06-bd-01/80 00000125 00000126 Core Ultra 200 V Series Processor SPR-SP E4/S2 06-8f-07/87 2b000661 2b000670 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000661 2b000670 Xeon Scalable Gen4 SRF-AP/SP C0 06-af-03/01 03000382 030003a3 Xeon 6900/6700-Series Processors with E-Cores ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2981=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-2981=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ucode-intel-debugsource-20260512-161.1 * ucode-intel-debuginfo-20260512-161.1 * ucode-intel-20260512-161.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * ucode-intel-debugsource-20260512-161.1 * ucode-intel-debuginfo-20260512-161.1 * ucode-intel-20260512-161.1 ## References: * https://www.suse.com/security/cve/CVE-2025-35979.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 08:30:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 08:30:25 -0000 Subject: SUSE-SU-2026:2994-1: important: Security update for the Linux Kernel (Live Patch 80 for SUSE Linux Enterprise 12 SP5) Message-ID: <178410422503.225.13617706644599692788@f4f3e2688bac> # Security update for the Linux Kernel (Live Patch 80 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2994-1 Release Date: 2026-07-14T19:33:35Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.302 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2994=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_302-default-5-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 08:30:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 08:30:37 -0000 Subject: SUSE-SU-2026:2993-1: important: Security update for the Linux Kernel (Live Patch 55 for SUSE Linux Enterprise 15 SP4) Message-ID: <178410423788.225.17990930873299337510@f4f3e2688bac> # Security update for the Linux Kernel (Live Patch 55 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:2993-1 Release Date: 2026-07-14T16:33:46Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.222 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-2993=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-2993=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_55-debugsource-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-2-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_55-debugsource-2-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:30:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:30:18 -0000 Subject: SUSE-SU-2026:3008-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP6) Message-ID: <178411861825.328.13544403067703311434@178315a69387> # Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:3008-1 Release Date: 2026-07-15T07:34:00Z Rating: important References: * bsc#1267723 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46173 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.118 fixes various security issues The following security issues were fixed: * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3008=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3008=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_118-default-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-2-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_118-default-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-2-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:30:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:30:30 -0000 Subject: SUSE-SU-2026:3009-1: important: Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5) Message-ID: <178411863014.328.15101004765618087186@178315a69387> # Security update for the Linux Kernel (Live Patch 42 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3009-1 Release Date: 2026-07-15T07:34:15Z Rating: important References: * bsc#1267723 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-46173 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.172 fixes various security issues The following security issues were fixed: * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3009=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3007=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3007=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3009=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_56-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_56-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-2-150400.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_172-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_42-debugsource-2-150500.2.2 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_172-default-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_172-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_42-debugsource-2-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:30:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:30:44 -0000 Subject: SUSE-SU-2026:3002-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) Message-ID: <178411864471.328.11985175415926280945@178315a69387> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:3002-1 Release Date: 2026-07-15T06:05:21Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.115 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-3002=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3002=1 ## Package List: * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_115-default-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-2-150600.2.2 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_115-default-2-150600.2.2 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-2-150600.2.2 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-2-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:31:03 -0000 Subject: SUSE-SU-2026:3001-1: important: Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP5) Message-ID: <178411866363.328.5384569409548264234@178315a69387> # Security update for the Linux Kernel (Live Patch 41 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:3001-1 Release Date: 2026-07-15T06:05:06Z Rating: important References: * bsc#1264094 * bsc#1265117 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 Cross-References: * CVE-2026-31758 * CVE-2026-43366 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.169 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3001=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3001=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_169-default-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_41-debugsource-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-2-150500.2.2 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-2-150500.2.2 * kernel-livepatch-SLE15-SP5_Update_41-debugsource-2-150500.2.2 * kernel-livepatch-5_14_21-150500_55_169-default-2-150500.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:31:25 -0000 Subject: SUSE-SU-2026:2997-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) Message-ID: <178411868555.328.11568143824485254540@178315a69387> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:2997-1 Release Date: 2026-07-15T04:04:34Z Rating: important References: * bsc#1264094 * bsc#1265197 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31758 * CVE-2026-43037 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31758 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31758 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31758 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.112 fixes various security issues The following security issues were fixed: * CVE-2026-31758: usb: usbtmc: Flush anchored URBs in usbtmc_release (bsc#1264094). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-2997=1 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-2997=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_26-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-3-150600.2.2 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_26-debugsource-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-3-150600.2.2 * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-3-150600.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31758.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1264094 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:31:41 -0000 Subject: SUSE-SU-2026:2995-1: important: Security update for the Linux Kernel (Live Patch 79 for SUSE Linux Enterprise 12 SP5) Message-ID: <178411870111.328.5169013593054760304@178315a69387> # Security update for the Linux Kernel (Live Patch 79 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:2995-1 Release Date: 2026-07-15T06:49:39Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.299 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-2995=1 SUSE-SLE-Live- Patching-12-SP5-2026-3003=1 SUSE-SLE-Live-Patching-12-SP5-2026-2999=1 SUSE-SLE- Live-Patching-12-SP5-2026-2996=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_283-default-10-2.1 * kgraft-patch-4_12_14-122_299-default-6-2.1 * kgraft-patch-4_12_14-122_275-default-12-2.1 * kgraft-patch-4_12_14-122_261-default-18-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:31:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:31:59 -0000 Subject: SUSE-SU-2026:3005-1: moderate: Security update for openssl-3 Message-ID: <178411871912.328.3088011483394354141@178315a69387> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3005-1 Release Date: 2026-07-15T07:26:31Z Rating: moderate References: * bsc#1266344 * bsc#1266350 Cross-References: * CVE-2026-34182 * CVE-2026-42767 CVSS scores: * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3005=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3005=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3005=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3005=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3005=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (noarch) * openssl-3-doc-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libopenssl3-64bit-3.0.8-150500.5.69.1 * libopenssl-3-devel-64bit-3.0.8-150500.5.69.1 * libopenssl3-64bit-debuginfo-3.0.8-150500.5.69.1 * openSUSE Leap 15.5 (x86_64) * libopenssl3-32bit-3.0.8-150500.5.69.1 * libopenssl-3-devel-32bit-3.0.8-150500.5.69.1 * libopenssl3-32bit-debuginfo-3.0.8-150500.5.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-debuginfo-3.0.8-150500.5.69.1 * openssl-3-3.0.8-150500.5.69.1 * openssl-3-debugsource-3.0.8-150500.5.69.1 * libopenssl3-3.0.8-150500.5.69.1 * libopenssl-3-devel-3.0.8-150500.5.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266344 * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:32:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:32:05 -0000 Subject: SUSE-SU-2026:3004-1: moderate: Security update for openssl-3 Message-ID: <178411872521.328.15442739738676712086@178315a69387> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3004-1 Release Date: 2026-07-15T07:26:12Z Rating: moderate References: * bsc#1266350 Cross-References: * CVE-2026-42767 CVSS scores: * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for openssl-3 fixes the following issue * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3004=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3004=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3004=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (x86_64) * libopenssl-3-devel-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (noarch) * openssl-3-doc-3.1.4-150600.5.56.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libopenssl-3-devel-64bit-3.1.4-150600.5.56.1 * libopenssl3-64bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-64bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-64bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-64bit-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libopenssl-3-fips-provider-32bit-3.1.4-150600.5.56.1 * libopenssl3-32bit-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.1.4-150600.5.56.1 * libopenssl3-32bit-debuginfo-3.1.4-150600.5.56.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-3.1.4-150600.5.56.1 * libopenssl3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-debuginfo-3.1.4-150600.5.56.1 * openssl-3-3.1.4-150600.5.56.1 * libopenssl3-3.1.4-150600.5.56.1 * openssl-3-debugsource-3.1.4-150600.5.56.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-150600.5.56.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 12:32:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 12:32:10 -0000 Subject: SUSE-SU-2026:3000-1: important: Security update for rootlesskit Message-ID: <178411873010.328.6804372493158678952@178315a69387> # Security update for rootlesskit Announcement ID: SUSE-SU-2026:3000-1 Release Date: 2026-07-15T05:04:34Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for rootlesskit rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3000=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3000=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3000=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3000=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150600.3.8.1 * rootlesskit-debuginfo-1.1.1-150600.3.8.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:30:41 -0000 Subject: SUSE-SU-2026:22604-1: low: Security update for patch Message-ID: <178413304171.13854.12584456474834967821@fcb35a5fe5ab> # Security update for patch Announcement ID: SUSE-SU-2026:22604-1 Release Date: 2026-07-13T19:29:50Z Rating: low References: * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1236=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * patch-2.7.6-160000.4.1 * patch-debugsource-2.7.6-160000.4.1 * patch-debuginfo-2.7.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:30:47 -0000 Subject: SUSE-SU-2026:22603-1: low: Security update for helm Message-ID: <178413304732.13854.2176255279438608619@fcb35a5fe5ab> # Security update for helm Announcement ID: SUSE-SU-2026:22603-1 Release Date: 2026-07-13T19:24:02Z Rating: low References: * bsc#1270127 Cross-References: * CVE-2026-48978 CVSS scores: * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: * Update to version 3.21.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1235=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-160000.2.1 * helm-3.21.2-160000.2.1 * SUSE Linux Micro 6.2 (noarch) * helm-bash-completion-3.21.2-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:30:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:30:54 -0000 Subject: SUSE-SU-2026:22602-1: moderate: Security update for cryptsetup Message-ID: <178413305454.13854.15374023338620349868@fcb35a5fe5ab> # Security update for cryptsetup Announcement ID: SUSE-SU-2026:22602-1 Release Date: 2026-07-13T16:23:16Z Rating: moderate References: * bsc#1270252 * bsc#1270254 Affected Products: * SUSE Linux Micro 6.2 An update that has two fixes can now be installed. ## Description: This update for cryptsetup fixes the following issues: Changes in cryptsetup: * Fix for (bsc#1270254) to avoid undesired pinning of all volume keys (via the thread keyring) through the caller's credentials when the kernel opens a file. This is due to the refactoring in kernel commit a28d893eb327 ("md: port block device access to file") that accidentally causes the caller's thread keyring to be kept alive long beyond the caller's lifetime, the kernel part is tracked in (bsc#1270252). * Add keyring key type. [b6fb6fc0] * Load volume keys in intermediary keyring linked in thread keyring. [413a3dd0] * Use unique intermediary keyring name per device. [04ef07a7] * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1229=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * cryptsetup-debugsource-2.8.4-160000.2.1 * cryptsetup-2.8.4-160000.2.1 * libcryptsetup12-2.8.4-160000.2.1 * cryptsetup-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-debuginfo-2.8.4-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270252 * https://bugzilla.suse.com/show_bug.cgi?id=1270254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:31:14 -0000 Subject: SUSE-SU-2026:22599-1: moderate: Security update for pam Message-ID: <178413307417.13854.8269966335084017418@fcb35a5fe5ab> # Security update for pam Announcement ID: SUSE-SU-2026:22599-1 Release Date: 2026-07-13T13:54:56Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1224=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * pam-extra-debuginfo-1.7.1-160000.5.1 * pam-extra-1.7.1-160000.5.1 * pam-1.7.1-160000.5.1 * pam-debuginfo-1.7.1-160000.5.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x) * pam-full-src-debugsource-1.7.1-160000.5.1 * pam-debugsource-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:31:48 -0000 Subject: SUSE-SU-2026:22598-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178413310816.13854.1711590946651379406@fcb35a5fe5ab> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:22598-1 Release Date: 2026-07-13T11:25:37Z Rating: important References: * bsc#1262759 * bsc#1263094 * bsc#1263177 * bsc#1263670 * bsc#1264252 * bsc#1264253 * bsc#1264567 * bsc#1264849 * bsc#1265117 * bsc#1265197 * bsc#1265945 * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-31505 * CVE-2026-31533 * CVE-2026-31586 * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43027 * CVE-2026-43037 * CVE-2026-43120 * CVE-2026-43190 * CVE-2026-43366 * CVE-2026-43494 * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-31505 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31505 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31505 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31533 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31533 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31586 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31586 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43027 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43027 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43120 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43366 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43366 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43494 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43494 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues The following security issues were fixed: * CVE-2026-31505: iavf: fix out-of-bounds writes in iavf_get_ethtool_stats() (bsc#1263094). * CVE-2026-31533: net/tls: fix use-after-free in -EBUSY error path of tls_do_encryption (bsc#1262759). * CVE-2026-31586: mm: blk-cgroup: fix use-after-free in cgwb_release_workfn() (bsc#1263177). * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43027: netfilter: nf_conntrack_helper: pass helper to expect cleanup (bsc#1264252). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43120: RDMA/irdma: Fix double free related to rereg_user_mr (bsc#1264567). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43366: io_uring/kbuf: check if target buffer list is still legacy on recycle (bsc#1265117). * CVE-2026-43494: RDS zerocopy attack aka PinTheft (bsc#1265945). * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1222=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_9-debugsource-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-4-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-debuginfo-4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31505.html * https://www.suse.com/security/cve/CVE-2026-31533.html * https://www.suse.com/security/cve/CVE-2026-31586.html * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43027.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43120.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43366.html * https://www.suse.com/security/cve/CVE-2026-43494.html * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1262759 * https://bugzilla.suse.com/show_bug.cgi?id=1263094 * https://bugzilla.suse.com/show_bug.cgi?id=1263177 * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264252 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264567 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265117 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1265945 * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:31:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:31:58 -0000 Subject: SUSE-SU-2026:22597-1: important: Security update for jq Message-ID: <178413311878.13854.7722716721197269576@fcb35a5fe5ab> # Security update for jq Announcement ID: SUSE-SU-2026:22597-1 Release Date: 2026-07-13T10:47:46Z Rating: important References: * bsc#1265075 * bsc#1265076 * bsc#1269220 * bsc#1269390 Cross-References: * CVE-2026-43896 * CVE-2026-44777 * CVE-2026-49839 * CVE-2026-54679 CVSS scores: * CVE-2026-43896 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44777 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44777 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-54679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues * CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized- string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). * CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1221=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-160000.4.1 * jq-debuginfo-1.7.1-160000.4.1 * jq-debugsource-1.7.1-160000.4.1 * libjq1-1.7.1-160000.4.1 * libjq1-debuginfo-1.7.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43896.html * https://www.suse.com/security/cve/CVE-2026-44777.html * https://www.suse.com/security/cve/CVE-2026-49839.html * https://www.suse.com/security/cve/CVE-2026-54679.html * https://bugzilla.suse.com/show_bug.cgi?id=1265075 * https://bugzilla.suse.com/show_bug.cgi?id=1265076 * https://bugzilla.suse.com/show_bug.cgi?id=1269220 * https://bugzilla.suse.com/show_bug.cgi?id=1269390 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:32:06 -0000 Subject: SUSE-SU-2026:22596-1: important: Security update for libxml2 Message-ID: <178413312676.13854.9634941002177174549@fcb35a5fe5ab> # Security update for libxml2 Announcement ID: SUSE-SU-2026:22596-1 Release Date: 2026-07-13T07:49:58Z Rating: important References: * bsc#1262719 * bsc#1269790 Cross-References: * CVE-2026-11979 * CVE-2026-6732 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6732 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6732 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for libxml2 fixes the following issues * CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719). * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1220=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libxml2-tools-debuginfo-2.13.8-160000.5.1 * libxml2-2-debuginfo-2.13.8-160000.5.1 * libxml2-2-2.13.8-160000.5.1 * python313-libxml2-debuginfo-2.13.8-160000.5.1 * libxml2-debugsource-2.13.8-160000.5.1 * python313-libxml2-2.13.8-160000.5.1 * libxml2-python-debugsource-2.13.8-160000.5.1 * libxml2-tools-2.13.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://www.suse.com/security/cve/CVE-2026-6732.html * https://bugzilla.suse.com/show_bug.cgi?id=1262719 * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:32:16 -0000 Subject: SUSE-SU-2026:22594-1: moderate: Security update for nghttp2 Message-ID: <178413313631.13854.5024843700544856887@fcb35a5fe5ab> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:22594-1 Release Date: 2026-07-10T13:25:42Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1213=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * nghttp2-debugsource-1.64.0-160000.4.1 * libnghttp2-14-1.64.0-160000.4.1 * nghttp2-debuginfo-1.64.0-160000.4.1 * libnghttp2-14-debuginfo-1.64.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:32:34 -0000 Subject: SUSE-SU-2026:22593-1: important: Security update for python-cryptography Message-ID: <178413315416.13854.12418635630649255225@fcb35a5fe5ab> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:22593-1 Release Date: 2026-07-10T09:12:46Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1205=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-cryptography-44.0.3-160000.4.1 * python-cryptography-debugsource-44.0.3-160000.4.1 * python313-cryptography-debuginfo-44.0.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:32:41 -0000 Subject: SUSE-SU-2026:22592-1: important: Security update for perl-DBI Message-ID: <178413316126.13854.16190621860706992943@fcb35a5fe5ab> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22592-1 Release Date: 2026-07-10T09:10:39Z Rating: important References: * bsc#1271017 * bsc#1271018 Cross-References: * CVE-2026-14380 * CVE-2026-14740 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1204=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.647.0-160000.4.1 * perl-DBI-1.647.0-160000.4.1 * perl-DBI-debuginfo-1.647.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:32:47 -0000 Subject: SUSE-SU-2026:22591-1: important: Security update for sssd Message-ID: <178413316797.13854.11531422031388546969@fcb35a5fe5ab> # Security update for sssd Announcement ID: SUSE-SU-2026:22591-1 Release Date: 2026-07-10T08:58:36Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1201=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libsss_certmap0-2.10.2-160000.3.1 * sssd-tools-debuginfo-2.10.2-160000.3.1 * sssd-dbus-2.10.2-160000.3.1 * libsss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-2.10.2-160000.3.1 * sssd-ad-debuginfo-2.10.2-160000.3.1 * python3-sssd-config-debuginfo-2.10.2-160000.3.1 * sssd-debugsource-2.10.2-160000.3.1 * sssd-debuginfo-2.10.2-160000.3.1 * libsss_certmap0-debuginfo-2.10.2-160000.3.1 * sssd-krb5-2.10.2-160000.3.1 * sssd-ldap-2.10.2-160000.3.1 * sssd-dbus-debuginfo-2.10.2-160000.3.1 * sssd-2.10.2-160000.3.1 * sssd-ad-2.10.2-160000.3.1 * sssd-ldap-debuginfo-2.10.2-160000.3.1 * libsss_idmap0-debuginfo-2.10.2-160000.3.1 * sssd-krb5-common-debuginfo-2.10.2-160000.3.1 * sssd-krb5-common-2.10.2-160000.3.1 * sssd-krb5-debuginfo-2.10.2-160000.3.1 * sssd-tools-2.10.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:32:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:32:55 -0000 Subject: SUSE-SU-2026:22590-1: important: Security update for tiff Message-ID: <178413317572.13854.16214657596489145858@fcb35a5fe5ab> # Security update for tiff Announcement ID: SUSE-SU-2026:22590-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 * CVE-2026-4775 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Changes for tiff: * Update to 4.7.2: Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss- fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg- turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss- fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1200=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * tiff-debugsource-4.7.2-160000.1.1 * libtiff6-4.7.2-160000.1.1 * libtiff6-debuginfo-4.7.2-160000.1.1 * tiff-debuginfo-4.7.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:33:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:33:12 -0000 Subject: SUSE-SU-2026:22589-1: important: Security update for python-maturin Message-ID: <178413319274.13854.16270570381015170889@fcb35a5fe5ab> # Security update for python-maturin Announcement ID: SUSE-SU-2026:22589-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-maturin fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1196=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-maturin-1.8.7-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:33:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:33:36 -0000 Subject: SUSE-SU-2026:3011-1: important: Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) Message-ID: <178413321630.13854.6526999483996110518@fcb35a5fe5ab> # Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3011-1 Release Date: 2026-07-15T08:46:04Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.307 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3011=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_307-default-3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:34:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:34:21 -0000 Subject: SUSE-SU-2026:3044-1: important: Security update for the Linux Kernel Message-ID: <178413326137.13854.9853238803080839712@fcb35a5fe5ab> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3044-1 Release Date: 2026-07-15T11:59:54Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 28 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: hci_event: move wake reason storage into validated event handlers (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-3044=1 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-3044=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3044=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3044=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3044=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3044=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3044=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3044=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3044=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3044=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3044=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * kernel-64kb-devel-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (s390x) * kernel-zfcpdump-debuginfo-5.14.21-150400.24.228.1 * kernel-zfcpdump-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64) * kernel-64kb-devel-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * kernel-64kb-devel-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * cluster-md-kmp-default-5.14.21-150400.24.228.1 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-5.14.21-150400.24.228.1 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * dlm-kmp-default-debuginfo-5.14.21-150400.24.228.1 * ocfs2-kmp-default-5.14.21-150400.24.228.1 * dlm-kmp-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (nosrc) * kernel-default-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64) * dtb-rockchip-5.14.21-150400.24.228.1 * kselftests-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * cluster-md-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * dtb-amazon-5.14.21-150400.24.228.1 * kselftests-kmp-64kb-5.14.21-150400.24.228.1 * dtb-socionext-5.14.21-150400.24.228.1 * dtb-arm-5.14.21-150400.24.228.1 * ocfs2-kmp-64kb-5.14.21-150400.24.228.1 * kernel-64kb-optional-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-devel-5.14.21-150400.24.228.1 * dlm-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-64kb-5.14.21-150400.24.228.1 * dtb-exynos-5.14.21-150400.24.228.1 * dtb-broadcom-5.14.21-150400.24.228.1 * dtb-cavium-5.14.21-150400.24.228.1 * dtb-nvidia-5.14.21-150400.24.228.1 * dtb-hisilicon-5.14.21-150400.24.228.1 * dtb-xilinx-5.14.21-150400.24.228.1 * kernel-64kb-optional-5.14.21-150400.24.228.1 * dtb-renesas-5.14.21-150400.24.228.1 * dtb-amd-5.14.21-150400.24.228.1 * dtb-allwinner-5.14.21-150400.24.228.1 * dtb-sprd-5.14.21-150400.24.228.1 * kernel-64kb-debuginfo-5.14.21-150400.24.228.1 * kernel-64kb-extra-5.14.21-150400.24.228.1 * dtb-lg-5.14.21-150400.24.228.1 * reiserfs-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * dtb-altera-5.14.21-150400.24.228.1 * dlm-kmp-64kb-5.14.21-150400.24.228.1 * kernel-64kb-debugsource-5.14.21-150400.24.228.1 * gfs2-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * dtb-freescale-5.14.21-150400.24.228.1 * dtb-qcom-5.14.21-150400.24.228.1 * dtb-amlogic-5.14.21-150400.24.228.1 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.228.1 * dtb-marvell-5.14.21-150400.24.228.1 * reiserfs-kmp-64kb-5.14.21-150400.24.228.1 * ocfs2-kmp-64kb-debuginfo-5.14.21-150400.24.228.1 * cluster-md-kmp-64kb-5.14.21-150400.24.228.1 * dtb-apple-5.14.21-150400.24.228.1 * kernel-64kb-extra-debuginfo-5.14.21-150400.24.228.1 * dtb-mediatek-5.14.21-150400.24.228.1 * dtb-apm-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * cluster-md-kmp-default-5.14.21-150400.24.228.1 * kernel-default-extra-5.14.21-150400.24.228.1 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.228.1 * ocfs2-kmp-default-5.14.21-150400.24.228.1 * dlm-kmp-default-5.14.21-150400.24.228.1 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-optional-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-extra-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-qa-5.14.21-150400.24.228.1 * kselftests-kmp-default-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * dlm-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kselftests-kmp-default-debuginfo-5.14.21-150400.24.228.1 * gfs2-kmp-default-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * kernel-default-livepatch-5.14.21-150400.24.228.1 * kernel-default-optional-5.14.21-150400.24.228.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * kernel-docs-html-5.14.21-150400.24.228.1 * kernel-source-vanilla-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-kvmsmall-debuginfo-5.14.21-150400.24.228.1 * kernel-kvmsmall-devel-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * kernel-default-base-rebuild-5.14.21-150400.24.228.1.150400.24.116.1 * kernel-kvmsmall-debugsource-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-default-livepatch-devel-5.14.21-150400.24.228.1 * kernel-livepatch-5_14_21-150400_24_228-default-1-150400.9.3.1 * kernel-livepatch-5_14_21-150400_24_228-default-debuginfo-1-150400.9.3.1 * kernel-livepatch-SLE15-SP4_Update_57-debugsource-1-150400.9.3.1 * openSUSE Leap 15.4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (nosrc) * dtb-aarch64-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-5.14.21-150400.24.228.1 * openSUSE Leap 15.4 (s390x) * kernel-zfcpdump-debugsource-5.14.21-150400.24.228.1 * kernel-zfcpdump-debuginfo-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-default-livepatch-5.14.21-150400.24.228.1 * kernel-livepatch-5_14_21-150400_24_228-default-debuginfo-1-150400.9.3.1 * kernel-default-livepatch-devel-5.14.21-150400.24.228.1 * kernel-livepatch-5_14_21-150400_24_228-default-1-150400.9.3.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-livepatch-SLE15-SP4_Update_57-debugsource-1-150400.9.3.1 * SUSE Linux Enterprise Live Patching 15-SP4 (nosrc) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kernel-default-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-debuginfo-5.14.21-150400.24.228.1 * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.228.1 * kernel-syms-5.14.21-150400.24.228.1 * reiserfs-kmp-default-5.14.21-150400.24.228.1 * kernel-obs-build-debugsource-5.14.21-150400.24.228.1 * kernel-default-devel-5.14.21-150400.24.228.1 * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-obs-build-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * kernel-devel-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * kernel-default-debuginfo-5.14.21-150400.24.228.1 * kernel-default-debugsource-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-macros-5.14.21-150400.24.228.1 * kernel-source-5.14.21-150400.24.228.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.228.1.150400.24.116.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.228.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:02 -0000 Subject: SUSE-SU-2026:3043-1: important: Security update for curl Message-ID: <178413330263.13854.8117277274851106164@fcb35a5fe5ab> # Security update for curl Announcement ID: SUSE-SU-2026:3043-1 Release Date: 2026-07-15T11:51:45Z Rating: important References: * bsc#1268402 * bsc#1268407 * bsc#1268409 * bsc#1268413 * bsc#1268415 * bsc#1268416 * bsc#1268417 * bsc#1268420 * bsc#1268422 * bsc#1268427 Cross-References: * CVE-2026-10536 * CVE-2026-12064 * CVE-2026-8286 * CVE-2026-8458 * CVE-2026-8924 * CVE-2026-8927 * CVE-2026-9079 * CVE-2026-9080 * CVE-2026-9545 * CVE-2026-9547 CVSS scores: * CVE-2026-10536 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10536 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-12064 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-12064 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-12064 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8286 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8286 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8286 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8458 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-8458 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-8458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-8924 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-8924 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-8924 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-8927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8927 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9079 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9079 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9079 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-9080 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9080 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9080 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-9545 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-9545 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-9547 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-9547 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-9547 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues * CVE-2026-8286: wrong STARTTLS connection reuse (bsc#1268402). * CVE-2026-8458: wrong reuse for different services (bsc#1268407). * CVE-2026-8924: traling dot domain super cookie (bsc#1268409). * CVE-2026-8927: env-set cross-proxy Digest auth state leak (bsc#1268413). * CVE-2026-9079: stale proxy password leak (bsc#1268415). * CVE-2026-9080: UAF after pause in socket callback (bsc#1268416). * CVE-2026-9545: exposing HTTP/3 early data (bsc#1268417). * CVE-2026-9547: SSH improper host validation (bsc#1268420). * CVE-2026-10536: HTTP/2 stream-dependency tree UAF (bsc#1268422). * CVE-2026-12064: proto-default skips SSH verification (bsc#1268427). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3043=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3043=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3043=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 SUSE-SLE-Product- SLES_SAP-15-SP5-2026-3043=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3043=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3043=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3043=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3043=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3043=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3043=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3043=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 SUSE-SLE-Product- SLES_SAP-15-SP4-2026-3043=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3043=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3043=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3043=1 * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-3043=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * curl-mini-debugsource-8.14.1-150400.5.86.1 * libcurl-mini4-8.14.1-150400.5.86.1 * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-mini4-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-32bit-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (noarch) * curl-zsh-completion-8.14.1-150400.5.86.1 * libcurl-devel-doc-8.14.1-150400.5.86.1 * curl-fish-completion-8.14.1-150400.5.86.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libcurl4-64bit-8.14.1-150400.5.86.1 * libcurl-devel-64bit-8.14.1-150400.5.86.1 * libcurl4-64bit-debuginfo-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * curl-debuginfo-8.14.1-150400.5.86.1 * libcurl-devel-8.14.1-150400.5.86.1 * libcurl4-debuginfo-8.14.1-150400.5.86.1 * curl-debugsource-8.14.1-150400.5.86.1 * curl-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150400.5.86.1 * libcurl4-32bit-8.14.1-150400.5.86.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64 x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libcurl4-8.14.1-150400.5.86.1 * SUSE Manager Proxy 4.3 (x86_64) * libcurl4-8.14.1-150400.5.86.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10536.html * https://www.suse.com/security/cve/CVE-2026-12064.html * https://www.suse.com/security/cve/CVE-2026-8286.html * https://www.suse.com/security/cve/CVE-2026-8458.html * https://www.suse.com/security/cve/CVE-2026-8924.html * https://www.suse.com/security/cve/CVE-2026-8927.html * https://www.suse.com/security/cve/CVE-2026-9079.html * https://www.suse.com/security/cve/CVE-2026-9080.html * https://www.suse.com/security/cve/CVE-2026-9545.html * https://www.suse.com/security/cve/CVE-2026-9547.html * https://bugzilla.suse.com/show_bug.cgi?id=1268402 * https://bugzilla.suse.com/show_bug.cgi?id=1268407 * https://bugzilla.suse.com/show_bug.cgi?id=1268409 * https://bugzilla.suse.com/show_bug.cgi?id=1268413 * https://bugzilla.suse.com/show_bug.cgi?id=1268415 * https://bugzilla.suse.com/show_bug.cgi?id=1268416 * https://bugzilla.suse.com/show_bug.cgi?id=1268417 * https://bugzilla.suse.com/show_bug.cgi?id=1268420 * https://bugzilla.suse.com/show_bug.cgi?id=1268422 * https://bugzilla.suse.com/show_bug.cgi?id=1268427 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:08 -0000 Subject: SUSE-SU-2026:3042-1: important: Security update for gnutls Message-ID: <178413330872.13854.9377132309101764939@fcb35a5fe5ab> # Security update for gnutls Announcement ID: SUSE-SU-2026:3042-1 Release Date: 2026-07-15T11:50:16Z Rating: important References: * bsc#1263713 Cross-References: * CVE-2026-42014 CVSS scores: * CVE-2026-42014 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42014 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42014 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gnutls fixes the following issue * Rebase the CVE-2026-42014 patch to include a missing call to `p11_kit_uri_free()` in `gnutls_pkcs11_token_set_pin()` (bsc#1263713). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3042=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3042=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3042=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3042=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3042=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3042=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3042=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3042=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3042=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3042=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3042=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3042=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgnutls-devel-64bit-3.7.3-150400.4.62.1 * libgnutls30-64bit-debuginfo-3.7.3-150400.4.62.1 * libgnutls30-hmac-64bit-3.7.3-150400.4.62.1 * libgnutls30-64bit-3.7.3-150400.4.62.1 * openSUSE Leap 15.4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls-devel-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-guile-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-guile-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libgnutls-devel-3.7.3-150400.4.62.1 * gnutls-debugsource-3.7.3-150400.4.62.1 * libgnutls30-debuginfo-3.7.3-150400.4.62.1 * gnutls-debuginfo-3.7.3-150400.4.62.1 * libgnutlsxx28-debuginfo-3.7.3-150400.4.62.1 * gnutls-3.7.3-150400.4.62.1 * libgnutlsxx-devel-3.7.3-150400.4.62.1 * libgnutlsxx28-3.7.3-150400.4.62.1 * libgnutls30-3.7.3-150400.4.62.1 * libgnutls30-hmac-3.7.3-150400.4.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libgnutls30-32bit-3.7.3-150400.4.62.1 * libgnutls30-hmac-32bit-3.7.3-150400.4.62.1 * libgnutls30-32bit-debuginfo-3.7.3-150400.4.62.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42014.html * https://bugzilla.suse.com/show_bug.cgi?id=1263713 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:15 -0000 Subject: SUSE-SU-2026:3041-1: important: Security update for sssd Message-ID: <178413331569.13854.18243054222017362487@fcb35a5fe5ab> # Security update for sssd Announcement ID: SUSE-SU-2026:3041-1 Release Date: 2026-07-15T11:49:01Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3041=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsss_nss_idmap0-debuginfo-2.10.2-150700.9.34.1 * libsss_simpleifp-devel-2.10.2-150700.9.34.1 * sssd-tools-debuginfo-2.10.2-150700.9.34.1 * sssd-ldap-2.10.2-150700.9.34.1 * sssd-ad-2.10.2-150700.9.34.1 * sssd-krb5-common-2.10.2-150700.9.34.1 * sssd-kcm-debuginfo-2.10.2-150700.9.34.1 * sssd-proxy-2.10.2-150700.9.34.1 * libsss_simpleifp0-debuginfo-2.10.2-150700.9.34.1 * libsss_idmap0-debuginfo-2.10.2-150700.9.34.1 * libsss_nss_idmap0-2.10.2-150700.9.34.1 * libsss_idmap-devel-2.10.2-150700.9.34.1 * sssd-ad-debuginfo-2.10.2-150700.9.34.1 * libsss_certmap-devel-2.10.2-150700.9.34.1 * sssd-winbind-idmap-2.10.2-150700.9.34.1 * libsss_certmap0-debuginfo-2.10.2-150700.9.34.1 * libsss_nss_idmap-devel-2.10.2-150700.9.34.1 * sssd-dbus-debuginfo-2.10.2-150700.9.34.1 * sssd-krb5-debuginfo-2.10.2-150700.9.34.1 * sssd-2.10.2-150700.9.34.1 * libipa_hbac-devel-2.10.2-150700.9.34.1 * sssd-debuginfo-2.10.2-150700.9.34.1 * libipa_hbac0-2.10.2-150700.9.34.1 * sssd-tools-2.10.2-150700.9.34.1 * sssd-proxy-debuginfo-2.10.2-150700.9.34.1 * libsss_idmap0-2.10.2-150700.9.34.1 * sssd-winbind-idmap-debuginfo-2.10.2-150700.9.34.1 * sssd-ipa-2.10.2-150700.9.34.1 * python3-sssd-config-debuginfo-2.10.2-150700.9.34.1 * sssd-debugsource-2.10.2-150700.9.34.1 * sssd-ldap-debuginfo-2.10.2-150700.9.34.1 * sssd-krb5-common-debuginfo-2.10.2-150700.9.34.1 * python3-sssd-config-2.10.2-150700.9.34.1 * sssd-kcm-2.10.2-150700.9.34.1 * libsss_simpleifp0-2.10.2-150700.9.34.1 * libsss_certmap0-2.10.2-150700.9.34.1 * sssd-krb5-2.10.2-150700.9.34.1 * libipa_hbac0-debuginfo-2.10.2-150700.9.34.1 * sssd-ipa-debuginfo-2.10.2-150700.9.34.1 * sssd-dbus-2.10.2-150700.9.34.1 * Basesystem Module 15-SP7 (x86_64) * sssd-32bit-2.10.2-150700.9.34.1 * sssd-32bit-debuginfo-2.10.2-150700.9.34.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:33 -0000 Subject: SUSE-SU-2026:3040-1: important: Security update for python-cryptography Message-ID: <178413333317.13854.7758505565538177283@fcb35a5fe5ab> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:3040-1 Release Date: 2026-07-15T11:48:45Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3040=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3040=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3040=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3040=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3040=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3040=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3040=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3040=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3040=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3040=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-cryptography-41.0.3-150400.16.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:40 -0000 Subject: SUSE-SU-2026:3039-1: important: Security update for libpng12 Message-ID: <178413334016.13854.14296675686579205158@fcb35a5fe5ab> # Security update for libpng12 Announcement ID: SUSE-SU-2026:3039-1 Release Date: 2026-07-15T11:45:44Z Rating: important References: * bsc#1258020 Cross-References: * CVE-2026-25646 CVSS scores: * CVE-2026-25646 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-25646 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-25646 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libpng12 fixes the following issue * CVE-2026-25646: Heap buffer overflow vulnerability in png_set_dither/png_set_quantize (bsc#1258020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3039=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3039=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpng12-debugsource-1.2.59-20.17.1 * libpng12-0-1.2.59-20.17.1 * libpng12-compat-devel-1.2.59-20.17.1 * libpng12-devel-1.2.59-20.17.1 * libpng12-0-32bit-1.2.59-20.17.1 * libpng12-0-debuginfo-1.2.59-20.17.1 * libpng12-0-debuginfo-32bit-1.2.59-20.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpng12-debugsource-1.2.59-20.17.1 * libpng12-0-1.2.59-20.17.1 * libpng12-compat-devel-1.2.59-20.17.1 * libpng12-devel-1.2.59-20.17.1 * libpng12-0-debuginfo-1.2.59-20.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libpng12-0-32bit-1.2.59-20.17.1 * libpng12-0-debuginfo-32bit-1.2.59-20.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25646.html * https://bugzilla.suse.com/show_bug.cgi?id=1258020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:49 -0000 Subject: SUSE-SU-2026:3038-1: important: Security update for qemu Message-ID: <178413334960.13854.10321231646454059450@fcb35a5fe5ab> # Security update for qemu Announcement ID: SUSE-SU-2026:3038-1 Release Date: 2026-07-15T11:45:32Z Rating: important References: * bsc#1268061 * bsc#1268794 * bsc#1270133 * jsc#PED-14242 * jsc#PED-14279 Cross-References: * CVE-2026-3886 * CVE-2026-48004 * CVE-2026-48914 CVSS scores: * CVE-2026-3886 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-48004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48914 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H * CVE-2026-48914 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities and contains two features can now be installed. ## Description: This update for qemu fixes the following issues * CVE-2026-3886: QEMU calc_image_hostmem Integer Overflow Local Privilege Escalation Vulnerability (bsc#1268061). * CVE-2026-48004: heap use-after-free race condition allows a DoS by an unprivileged guest user (bsc#1270133). * CVE-2026-48914: qemu-kvm: Heap Buffer Overflow in virtio-blk SCSI Request Handling (bsc#1268794). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3038=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3038=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3038=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * qemu-ui-dbus-9.2.4-150700.3.23.1 * qemu-chardev-spice-9.2.4-150700.3.23.1 * qemu-ui-opengl-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-curses-9.2.4-150700.3.23.1 * qemu-audio-spice-9.2.4-150700.3.23.1 * qemu-hw-display-qxl-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-dbus-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pipewire-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-host-9.2.4-150700.3.23.1 * qemu-audio-spice-debuginfo-9.2.4-150700.3.23.1 * qemu-block-nfs-debuginfo-9.2.4-150700.3.23.1 * qemu-block-iscsi-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-opengl-9.2.4-150700.3.23.1 * qemu-ui-curses-debuginfo-9.2.4-150700.3.23.1 * qemu-block-curl-debuginfo-9.2.4-150700.3.23.1 * qemu-guest-agent-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-dbus-9.2.4-150700.3.23.1 * qemu-hw-usb-redirect-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-vga-debuginfo-9.2.4-150700.3.23.1 * qemu-9.2.4-150700.3.23.1 * qemu-debugsource-9.2.4-150700.3.23.1 * qemu-chardev-baum-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-redirect-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-vga-9.2.4-150700.3.23.1 * qemu-block-nfs-9.2.4-150700.3.23.1 * qemu-ksm-9.2.4-150700.3.23.1 * qemu-block-rbd-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-host-debuginfo-9.2.4-150700.3.23.1 * qemu-block-iscsi-9.2.4-150700.3.23.1 * qemu-debuginfo-9.2.4-150700.3.23.1 * qemu-headless-9.2.4-150700.3.23.1 * qemu-chardev-baum-9.2.4-150700.3.23.1 * qemu-ui-spice-core-9.2.4-150700.3.23.1 * qemu-block-rbd-9.2.4-150700.3.23.1 * qemu-block-curl-9.2.4-150700.3.23.1 * qemu-guest-agent-9.2.4-150700.3.23.1 * qemu-ui-spice-core-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-qxl-9.2.4-150700.3.23.1 * qemu-chardev-spice-debuginfo-9.2.4-150700.3.23.1 * qemu-block-ssh-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pipewire-9.2.4-150700.3.23.1 * qemu-spice-9.2.4-150700.3.23.1 * qemu-block-ssh-9.2.4-150700.3.23.1 * qemu-audio-dbus-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (s390x) * qemu-hw-s390x-virtio-gpu-ccw-9.2.4-150700.3.23.1 * qemu-s390x-9.2.4-150700.3.23.1 * qemu-s390x-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (aarch64 ppc64le x86_64) * qemu-ui-spice-app-debuginfo-9.2.4-150700.3.23.1 * qemu-ui-spice-app-9.2.4-150700.3.23.1 * qemu-ui-gtk-9.2.4-150700.3.23.1 * qemu-ui-gtk-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (aarch64 s390x x86_64) * qemu-hw-display-virtio-gpu-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (noarch) * qemu-vgabios-9.2.41.16.3_3_g3d33c746-150700.3.23.1 * qemu-seabios-9.2.41.16.3_3_g3d33c746-150700.3.23.1 * qemu-ipxe-9.2.4-150700.3.23.1 * qemu-skiboot-9.2.4-150700.3.23.1 * qemu-lang-9.2.4-150700.3.23.1 * qemu-SLOF-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (x86_64) * qemu-x86-9.2.4-150700.3.23.1 * qemu-audio-alsa-9.2.4-150700.3.23.1 * qemu-audio-alsa-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pa-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-pa-9.2.4-150700.3.23.1 * qemu-x86-debuginfo-9.2.4-150700.3.23.1 * qemu-accel-tcg-x86-debuginfo-9.2.4-150700.3.23.1 * qemu-accel-tcg-x86-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (aarch64) * qemu-arm-9.2.4-150700.3.23.1 * qemu-arm-debuginfo-9.2.4-150700.3.23.1 * Server Applications Module 15-SP7 (ppc64le) * qemu-ppc-debuginfo-9.2.4-150700.3.23.1 * qemu-ppc-9.2.4-150700.3.23.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * qemu-audio-jack-9.2.4-150700.3.23.1 * qemu-vhost-user-gpu-9.2.4-150700.3.23.1 * qemu-vhost-user-gpu-debuginfo-9.2.4-150700.3.23.1 * qemu-s390x-9.2.4-150700.3.23.1 * qemu-linux-user-9.2.4-150700.3.23.1 * qemu-hw-s390x-virtio-gpu-ccw-debuginfo-9.2.4-150700.3.23.1 * qemu-ivshmem-tools-9.2.4-150700.3.23.1 * qemu-linux-user-debugsource-9.2.4-150700.3.23.1 * qemu-block-dmg-debuginfo-9.2.4-150700.3.23.1 * qemu-extra-9.2.4-150700.3.23.1 * qemu-accel-qtest-debuginfo-9.2.4-150700.3.23.1 * qemu-linux-user-debuginfo-9.2.4-150700.3.23.1 * qemu-ivshmem-tools-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-usb-smartcard-9.2.4-150700.3.23.1 * qemu-debugsource-9.2.4-150700.3.23.1 * qemu-hw-s390x-virtio-gpu-ccw-9.2.4-150700.3.23.1 * qemu-arm-debuginfo-9.2.4-150700.3.23.1 * qemu-extra-debuginfo-9.2.4-150700.3.23.1 * qemu-block-dmg-9.2.4-150700.3.23.1 * qemu-s390x-debuginfo-9.2.4-150700.3.23.1 * qemu-ppc-debuginfo-9.2.4-150700.3.23.1 * qemu-accel-qtest-9.2.4-150700.3.23.1 * qemu-arm-9.2.4-150700.3.23.1 * qemu-hw-usb-smartcard-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-jack-debuginfo-9.2.4-150700.3.23.1 * qemu-debuginfo-9.2.4-150700.3.23.1 * qemu-audio-oss-9.2.4-150700.3.23.1 * qemu-ppc-9.2.4-150700.3.23.1 * qemu-audio-oss-debuginfo-9.2.4-150700.3.23.1 * SUSE Package Hub 15 15-SP7 (noarch) * qemu-microvm-9.2.4-150700.3.23.1 * qemu-SLOF-9.2.4-150700.3.23.1 * qemu-skiboot-9.2.4-150700.3.23.1 * SUSE Package Hub 15 15-SP7 (ppc64le) * qemu-hw-display-virtio-gpu-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-pci-debuginfo-9.2.4-150700.3.23.1 * qemu-hw-display-virtio-gpu-debuginfo-9.2.4-150700.3.23.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * qemu-pr-helper-9.2.4-150700.3.23.1 * qemu-img-9.2.4-150700.3.23.1 * qemu-img-debuginfo-9.2.4-150700.3.23.1 * qemu-debuginfo-9.2.4-150700.3.23.1 * qemu-debugsource-9.2.4-150700.3.23.1 * qemu-tools-debuginfo-9.2.4-150700.3.23.1 * qemu-tools-9.2.4-150700.3.23.1 * qemu-pr-helper-debuginfo-9.2.4-150700.3.23.1 * Basesystem Module 15-SP7 (x86_64) * qemu-vmsr-helper-9.2.4-150700.3.23.1 * qemu-vmsr-helper-debuginfo-9.2.4-150700.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-3886.html * https://www.suse.com/security/cve/CVE-2026-48004.html * https://www.suse.com/security/cve/CVE-2026-48914.html * https://bugzilla.suse.com/show_bug.cgi?id=1268061 * https://bugzilla.suse.com/show_bug.cgi?id=1268794 * https://bugzilla.suse.com/show_bug.cgi?id=1270133 * https://jira.suse.com/browse/PED-14242 * https://jira.suse.com/browse/PED-14279 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:35:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:35:55 -0000 Subject: SUSE-SU-2026:3037-1: important: Security update for yelp Message-ID: <178413335530.13854.10964873445783659778@fcb35a5fe5ab> # Security update for yelp Announcement ID: SUSE-SU-2026:3037-1 Release Date: 2026-07-15T11:45:09Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3037=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3037=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3037=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3037=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3037=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3037=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3037=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3037=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3037=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * yelp-lang-41.2-150400.3.6.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * openSUSE Leap 15.4 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * yelp-debugsource-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * yelp-lang-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * yelp-debugsource-41.2-150400.3.6.1 * yelp-devel-41.2-150400.3.6.1 * yelp-debuginfo-41.2-150400.3.6.1 * libyelp0-debuginfo-41.2-150400.3.6.1 * yelp-41.2-150400.3.6.1 * libyelp0-41.2-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * yelp-lang-41.2-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:01 -0000 Subject: SUSE-SU-2026:3036-1: important: Security update for yelp Message-ID: <178413336118.13854.1177124147426746359@fcb35a5fe5ab> # Security update for yelp Announcement ID: SUSE-SU-2026:3036-1 Release Date: 2026-07-15T11:44:33Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3036=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3036=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3036=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3036=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * yelp-lang-42.2-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * yelp-lang-42.2-150600.3.6.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * Desktop Applications Module 15-SP7 (noarch) * yelp-lang-42.2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debugsource-42.2-150600.3.6.1 * libyelp0-42.2-150600.3.6.1 * yelp-devel-42.2-150600.3.6.1 * libyelp0-debuginfo-42.2-150600.3.6.1 * yelp-debuginfo-42.2-150600.3.6.1 * yelp-42.2-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * yelp-lang-42.2-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:06 -0000 Subject: SUSE-SU-2026:3035-1: important: Security update for yelp Message-ID: <178413336677.13854.3057058288734354081@fcb35a5fe5ab> # Security update for yelp Announcement ID: SUSE-SU-2026:3035-1 Release Date: 2026-07-15T11:44:17Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3035=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3035=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * yelp-debuginfo-3.20.1-7.6.1 * yelp-devel-3.20.1-7.6.1 * yelp-debugsource-3.20.1-7.6.1 * yelp-3.20.1-7.6.1 * libyelp0-3.20.1-7.6.1 * libyelp0-debuginfo-3.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * yelp-lang-3.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yelp-debuginfo-3.20.1-7.6.1 * yelp-debugsource-3.20.1-7.6.1 * yelp-devel-3.20.1-7.6.1 * yelp-3.20.1-7.6.1 * libyelp0-3.20.1-7.6.1 * libyelp0-debuginfo-3.20.1-7.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * yelp-lang-3.20.1-7.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:18 -0000 Subject: SUSE-SU-2026:3033-1: moderate: Security update for perl-libwww-perl Message-ID: <178413337803.13854.11432556942403050018@fcb35a5fe5ab> # Security update for perl-libwww-perl Announcement ID: SUSE-SU-2026:3033-1 Release Date: 2026-07-15T09:54:09Z Rating: moderate References: * bsc#1265156 Cross-References: * CVE-2026-8368 CVSS scores: * CVE-2026-8368 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-8368 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-libwww-perl fixes the following issue * CVE-2026-8368: LWP: UserAgent: Authorization and Proxy-Authorization headers are leaked on cross-origin redirects (bsc#1265156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3033=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * perl-libwww-perl-6.05-6.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-8368.html * https://bugzilla.suse.com/show_bug.cgi?id=1265156 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:23 -0000 Subject: SUSE-SU-2026:3032-1: moderate: Security update for glib-networking Message-ID: <178413338317.13854.16333542779426470957@fcb35a5fe5ab> # Security update for glib-networking Announcement ID: SUSE-SU-2026:3032-1 Release Date: 2026-07-15T09:53:56Z Rating: moderate References: * bsc#1267979 Cross-References: * CVE-2026-10028 CVSS scores: * CVE-2026-10028 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-10028 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-10028 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for glib-networking fixes the following issue * CVE-2026-10028: two certificates which are each signed by the other can lead to an infinite loop (bsc#1267979). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3032=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3032=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * glib-networking-debugsource-2.78.0-150600.3.3.1 * glib-networking-2.78.0-150600.3.3.1 * glib-networking-debuginfo-2.78.0-150600.3.3.1 * openSUSE Leap 15.6 (x86_64) * glib-networking-32bit-debuginfo-2.78.0-150600.3.3.1 * glib-networking-32bit-2.78.0-150600.3.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * glib-networking-64bit-debuginfo-2.78.0-150600.3.3.1 * glib-networking-64bit-2.78.0-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * glib-networking-lang-2.78.0-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glib-networking-debugsource-2.78.0-150600.3.3.1 * glib-networking-2.78.0-150600.3.3.1 * glib-networking-debuginfo-2.78.0-150600.3.3.1 * Basesystem Module 15-SP7 (noarch) * glib-networking-lang-2.78.0-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10028.html * https://bugzilla.suse.com/show_bug.cgi?id=1267979 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:28 -0000 Subject: SUSE-SU-2026:3031-1: moderate: Security update for python-paramiko Message-ID: <178413338871.13854.15450401620152834427@fcb35a5fe5ab> # Security update for python-paramiko Announcement ID: SUSE-SU-2026:3031-1 Release Date: 2026-07-15T09:53:45Z Rating: moderate References: * bsc#1264225 Cross-References: * CVE-2026-44405 CVSS scores: * CVE-2026-44405 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44405 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44405 ( NVD ): 3.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-paramiko fixes the following issues: * CVE-2026-44405: data integrity compromise due to allowed SHA-1 algorithm use (bsc#1264225). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3031=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python311-paramiko-3.5.1-150700.20.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44405.html * https://bugzilla.suse.com/show_bug.cgi?id=1264225 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:35 -0000 Subject: SUSE-SU-2026:3030-1: moderate: Security update for glibc Message-ID: <178413339562.13854.16083550109546984599@fcb35a5fe5ab> # Security update for glibc Announcement ID: SUSE-SU-2026:3030-1 Release Date: 2026-07-15T09:53:19Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3030=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3030=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3030=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3030=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3030=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * glibc-extra-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * glibc-utils-src-debugsource-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-extra-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * Basesystem Module 15-SP7 (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * Basesystem Module 15-SP7 (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (aarch64 i586 i686 ppc64le s390x x86_64) * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * openSUSE Leap 15.6 (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-utils-32bit-2.38-150600.14.52.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-profile-32bit-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 * glibc-devel-static-32bit-2.38-150600.14.52.1 * glibc-utils-32bit-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-extra-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (aarch64_ilp32) * glibc-locale-base-64bit-debuginfo-2.38-150600.14.52.1 * glibc-utils-64bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-static-64bit-2.38-150600.14.52.1 * glibc-64bit-debuginfo-2.38-150600.14.52.1 * libnsl1-64bit-2.38-150600.14.52.1 * glibc-devel-64bit-2.38-150600.14.52.1 * glibc-64bit-2.38-150600.14.52.1 * glibc-profile-64bit-2.38-150600.14.52.1 * glibc-utils-64bit-2.38-150600.14.52.1 * glibc-locale-base-64bit-2.38-150600.14.52.1 * glibc-devel-64bit-debuginfo-2.38-150600.14.52.1 * libnsl1-64bit-debuginfo-2.38-150600.14.52.1 * openSUSE Leap 15.6 (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * glibc-html-2.38-150600.14.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libnsl1-32bit-2.38-150600.14.52.1 * glibc-32bit-2.38-150600.14.52.1 * libnsl1-32bit-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-32bit-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * glibc-extra-2.38-150600.14.52.1 * glibc-locale-base-debuginfo-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * libnsl1-2.38-150600.14.52.1 * glibc-extra-debuginfo-2.38-150600.14.52.1 * nscd-2.38-150600.14.52.1 * glibc-devel-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * glibc-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * glibc-locale-base-2.38-150600.14.52.1 * glibc-devel-2.38-150600.14.52.1 * glibc-profile-2.38-150600.14.52.1 * glibc-locale-2.38-150600.14.52.1 * libnsl1-debuginfo-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * nscd-debuginfo-2.38-150600.14.52.1 * glibc-utils-src-debugsource-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * glibc-lang-2.38-150600.14.52.1 * glibc-i18ndata-2.38-150600.14.52.1 * glibc-info-2.38-150600.14.52.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.38-150600.14.52.1 * glibc-utils-debuginfo-2.38-150600.14.52.1 * glibc-debugsource-2.38-150600.14.52.1 * glibc-utils-2.38-150600.14.52.1 * glibc-debuginfo-2.38-150600.14.52.1 * glibc-devel-static-2.38-150600.14.52.1 * Development Tools Module 15-SP7 (x86_64) * glibc-devel-32bit-debuginfo-2.38-150600.14.52.1 * glibc-32bit-debuginfo-2.38-150600.14.52.1 * glibc-devel-32bit-2.38-150600.14.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:43 -0000 Subject: SUSE-SU-2026:3029-1: moderate: Security update for glibc Message-ID: <178413340308.13854.9781666211582972759@fcb35a5fe5ab> # Security update for glibc Announcement ID: SUSE-SU-2026:3029-1 Release Date: 2026-07-15T09:52:53Z Rating: moderate References: * bsc#1263656 * bsc#1263658 Cross-References: * CVE-2026-5435 * CVE-2026-6238 CVSS scores: * CVE-2026-5435 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-5435 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-5435 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-6238 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6238 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues * CVE-2026-5435: unchecked buffer writing in TSIG handling can lead to an out- of-bounds write (bsc#1263656). * CVE-2026-6238: insufficient RDATA length validation can lead to application crashes or uninitialized memory disclosure (bsc#1263658). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3029=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3029=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3029=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3029=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3029=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3029=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3029=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3029=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3029=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3029=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3029=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3029=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3029=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3029=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * openSUSE Leap 15.3 (aarch64 i586 i686 ppc64le s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * openSUSE Leap 15.3 (x86_64) * glibc-profile-32bit-2.31-150300.104.1 * glibc-utils-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-utils-32bit-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-devel-static-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * openSUSE Leap 15.3 (noarch) * glibc-html-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * openSUSE Leap 15.3 (aarch64_ilp32) * glibc-locale-base-64bit-debuginfo-2.31-150300.104.1 * glibc-64bit-2.31-150300.104.1 * glibc-profile-64bit-2.31-150300.104.1 * glibc-devel-64bit-2.31-150300.104.1 * glibc-64bit-debuginfo-2.31-150300.104.1 * glibc-devel-static-64bit-2.31-150300.104.1 * glibc-devel-64bit-debuginfo-2.31-150300.104.1 * glibc-utils-64bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-64bit-2.31-150300.104.1 * glibc-utils-64bit-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * glibc-lang-2.31-150300.104.1 * glibc-i18ndata-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * glibc-devel-32bit-2.31-150300.104.1 * glibc-locale-base-32bit-debuginfo-2.31-150300.104.1 * glibc-devel-32bit-debuginfo-2.31-150300.104.1 * glibc-32bit-debuginfo-2.31-150300.104.1 * glibc-locale-base-32bit-2.31-150300.104.1 * glibc-32bit-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * glibc-utils-src-debugsource-2.31-150300.104.1 * glibc-locale-2.31-150300.104.1 * glibc-utils-debuginfo-2.31-150300.104.1 * glibc-profile-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * nscd-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-utils-2.31-150300.104.1 * glibc-devel-static-2.31-150300.104.1 * glibc-extra-debuginfo-2.31-150300.104.1 * glibc-extra-2.31-150300.104.1 * nscd-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * glibc-i18ndata-2.31-150300.104.1 * glibc-lang-2.31-150300.104.1 * glibc-info-2.31-150300.104.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * glibc-locale-2.31-150300.104.1 * glibc-locale-base-2.31-150300.104.1 * glibc-devel-2.31-150300.104.1 * glibc-locale-base-debuginfo-2.31-150300.104.1 * glibc-2.31-150300.104.1 * glibc-devel-debuginfo-2.31-150300.104.1 * glibc-debugsource-2.31-150300.104.1 * glibc-debuginfo-2.31-150300.104.1 ## References: * https://www.suse.com/security/cve/CVE-2026-5435.html * https://www.suse.com/security/cve/CVE-2026-6238.html * https://bugzilla.suse.com/show_bug.cgi?id=1263656 * https://bugzilla.suse.com/show_bug.cgi?id=1263658 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:51 -0000 Subject: SUSE-SU-2026:3028-1: important: Security update for dnsmasq Message-ID: <178413341126.13854.8401115699431095006@fcb35a5fe5ab> # Security update for dnsmasq Announcement ID: SUSE-SU-2026:3028-1 Release Date: 2026-07-15T09:51:44Z Rating: important References: * bsc#1268764 * bsc#1268882 Cross-References: * CVE-2026-12725 * CVE-2026-12969 CVSS scores: * CVE-2026-12725 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-12725 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12725 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12969 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12969 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12969 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for dnsmasq fixes the following issues * CVE-2026-12725: heap buffer overflow in `log_query()` when logging unsupported DS/DNSKEY replies (bsc#1268764). * CVE-2026-12969: out-of-bounds read in `find_soa()` due to missing extrabytes validation (bsc#1268882). Changes for dnsmasq: * Update to 2.93: * Fix a corner-case in DNSSEC validation with wildcards. * Fix DNSSEC failure with spurious RRSIGs. * Fix DNSSEC fail with CNAME replies to DS queries. * Fix regression in 2.92 release which broke DHCPv6 when a DHCP relay is in use. * Modify the inotify implementation so that inotify watches are only created after dnsmasq has changed permissions and userid. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3028=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3028=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3028=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3028=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3028=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3028=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3028=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3028=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3028=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3028=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3028=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3028=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-utils-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * dnsmasq-utils-2.93-150400.16.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dnsmasq-debuginfo-2.93-150400.16.17.1 * dnsmasq-2.93-150400.16.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12725.html * https://www.suse.com/security/cve/CVE-2026-12969.html * https://bugzilla.suse.com/show_bug.cgi?id=1268764 * https://bugzilla.suse.com/show_bug.cgi?id=1268882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:36:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:36:57 -0000 Subject: SUSE-SU-2026:3027-1: important: Security update for tiff Message-ID: <178413341797.13854.4436696208123085806@fcb35a5fe5ab> # Security update for tiff Announcement ID: SUSE-SU-2026:3027-1 Release Date: 2026-07-15T09:49:58Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3027=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3027=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-44.115.1 * libtiff-devel-4.0.9-44.115.1 * tiff-debugsource-4.0.9-44.115.1 * libtiff5-debuginfo-4.0.9-44.115.1 * libtiff5-4.0.9-44.115.1 * tiff-4.0.9-44.115.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libtiff5-32bit-4.0.9-44.115.1 * libtiff5-debuginfo-32bit-4.0.9-44.115.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * tiff-debuginfo-4.0.9-44.115.1 * libtiff-devel-4.0.9-44.115.1 * libtiff5-debuginfo-32bit-4.0.9-44.115.1 * libtiff5-32bit-4.0.9-44.115.1 * tiff-debugsource-4.0.9-44.115.1 * libtiff5-debuginfo-4.0.9-44.115.1 * libtiff5-4.0.9-44.115.1 * tiff-4.0.9-44.115.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:37:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:37:14 -0000 Subject: SUSE-SU-2026:3026-1: important: Security update for python-cryptography Message-ID: <178413343458.13854.15666939470761155277@fcb35a5fe5ab> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:3026-1 Release Date: 2026-07-15T09:49:44Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270620). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270706). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270801). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3026=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3026=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3026=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3026=1 ## Package List: * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150600.23.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150600.23.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-cryptography-41.0.3-150600.23.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-cryptography-41.0.3-150600.23.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:37:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:37:21 -0000 Subject: SUSE-SU-2026:3025-1: important: Security update for sssd Message-ID: <178413344135.13854.12492843639923713178@fcb35a5fe5ab> # Security update for sssd Announcement ID: SUSE-SU-2026:3025-1 Release Date: 2026-07-15T09:49:27Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3025=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3025=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3025=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * python3-sss_nss_idmap-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * libnfsidmap-sss-debuginfo-2.10.2-150600.3.53.1 * python3-sss_nss_idmap-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * python3-ipa_hbac-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * python3-ipa_hbac-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * libnfsidmap-sss-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * python3-sss-murmur-debuginfo-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * python3-sss-murmur-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * openSUSE Leap 15.6 (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 * openSUSE Leap 15.6 (aarch64_ilp32) * sssd-64bit-2.10.2-150600.3.53.1 * sssd-64bit-debuginfo-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * sssd-dbus-2.10.2-150600.3.53.1 * libsss_certmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-debuginfo-2.10.2-150600.3.53.1 * libsss_simpleifp0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-2.10.2-150600.3.53.1 * libsss_simpleifp-devel-2.10.2-150600.3.53.1 * python3-sssd-config-2.10.2-150600.3.53.1 * sssd-krb5-common-debuginfo-2.10.2-150600.3.53.1 * python3-sssd-config-debuginfo-2.10.2-150600.3.53.1 * sssd-debugsource-2.10.2-150600.3.53.1 * sssd-proxy-2.10.2-150600.3.53.1 * sssd-ad-2.10.2-150600.3.53.1 * sssd-ldap-debuginfo-2.10.2-150600.3.53.1 * libsss_idmap0-2.10.2-150600.3.53.1 * libsss_nss_idmap0-2.10.2-150600.3.53.1 * sssd-ad-debuginfo-2.10.2-150600.3.53.1 * sssd-winbind-idmap-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-debuginfo-2.10.2-150600.3.53.1 * libipa_hbac0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap0-debuginfo-2.10.2-150600.3.53.1 * libsss_nss_idmap-devel-2.10.2-150600.3.53.1 * sssd-winbind-idmap-2.10.2-150600.3.53.1 * sssd-proxy-debuginfo-2.10.2-150600.3.53.1 * sssd-tools-2.10.2-150600.3.53.1 * sssd-2.10.2-150600.3.53.1 * libsss_idmap0-debuginfo-2.10.2-150600.3.53.1 * sssd-krb5-common-2.10.2-150600.3.53.1 * sssd-kcm-debuginfo-2.10.2-150600.3.53.1 * sssd-ldap-2.10.2-150600.3.53.1 * libipa_hbac0-2.10.2-150600.3.53.1 * sssd-debuginfo-2.10.2-150600.3.53.1 * sssd-kcm-2.10.2-150600.3.53.1 * libsss_simpleifp0-2.10.2-150600.3.53.1 * libsss_certmap0-2.10.2-150600.3.53.1 * libsss_certmap-devel-2.10.2-150600.3.53.1 * sssd-dbus-debuginfo-2.10.2-150600.3.53.1 * sssd-ipa-2.10.2-150600.3.53.1 * libipa_hbac-devel-2.10.2-150600.3.53.1 * libsss_idmap-devel-2.10.2-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * sssd-32bit-2.10.2-150600.3.53.1 * sssd-32bit-debuginfo-2.10.2-150600.3.53.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:38:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:38:02 -0000 Subject: SUSE-SU-2026:3024-1: important: Security update for ImageMagick Message-ID: <178413348255.13854.6901102617158970740@fcb35a5fe5ab> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3024-1 Release Date: 2026-07-15T09:49:13Z Rating: important References: * bsc#1265048 * bsc#1268092 * bsc#1268094 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268105 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268117 * bsc#1268120 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270004 * bsc#1270073 * bsc#1270074 Cross-References: * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53463 * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56371 * CVE-2026-56379 CVSS scores: * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 27 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-42050: stack buffer overflow in XTileImage (bsc#1265048). * CVE-2026-42326: information disclosure via malicious IPTC input file (bsc#1268092). * CVE-2026-45031: denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). * CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). * CVE-2026-45624: data exposure due to image processing vulnerability (bsc#1268096). * CVE-2026-45664: denial of Service due to excessive resource use in MNG coder (bsc#1268101). * CVE-2026-46520: denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). * CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). * CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). * CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). * CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). * CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). * CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). * CVE-2026-53466: heap Buffer Over-Read in XCF decoder due to integer conversion overflow (bsc#1270073). * CVE-2026-53467: information Disclosure in MNG decoder because allocated memory is left unchanged (bsc#1270074). * CVE-2026-56361: off-by-one origin validation in allows out-of-bounds read in morphology processing (bsc#1270001). * CVE-2026-56363: division by Zero in binomial kernel (bsc#1270002). * CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3024=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3024=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * libMagickCore-6_Q16-1-6.8.8.1-71.259.1 * libMagick++-devel-6.8.8.1-71.259.1 * ImageMagick-devel-6.8.8.1-71.259.1 * ImageMagick-config-6-upstream-6.8.8.1-71.259.1 * ImageMagick-debugsource-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * ImageMagick-debuginfo-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-6.8.8.1-71.259.1 * ImageMagick-config-6-SUSE-6.8.8.1-71.259.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * ImageMagick-devel-6.8.8.1-71.259.1 * libMagick++-devel-6.8.8.1-71.259.1 * libMagickCore-6_Q16-1-6.8.8.1-71.259.1 * ImageMagick-config-6-upstream-6.8.8.1-71.259.1 * ImageMagick-debugsource-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.259.1 * ImageMagick-debuginfo-6.8.8.1-71.259.1 * libMagickWand-6_Q16-1-6.8.8.1-71.259.1 * ImageMagick-config-6-SUSE-6.8.8.1-71.259.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:38:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:38:59 -0000 Subject: SUSE-SU-2026:3023-1: important: Security update for ImageMagick Message-ID: <178413353974.13854.11290770802739351519@fcb35a5fe5ab> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3023-1 Release Date: 2026-07-15T09:48:59Z Rating: important References: * bsc#1265048 * bsc#1268092 * bsc#1268094 * bsc#1268095 * bsc#1268096 * bsc#1268101 * bsc#1268102 * bsc#1268103 * bsc#1268105 * bsc#1268107 * bsc#1268108 * bsc#1268110 * bsc#1268111 * bsc#1268112 * bsc#1268113 * bsc#1268114 * bsc#1268117 * bsc#1268120 * bsc#1268121 * bsc#1268122 * bsc#1268123 * bsc#1268124 * bsc#1268125 * bsc#1268126 * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270004 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 * bsc#1271099 Cross-References: * CVE-2026-40169 * CVE-2026-42050 * CVE-2026-42326 * CVE-2026-45031 * CVE-2026-45358 * CVE-2026-45359 * CVE-2026-45624 * CVE-2026-45664 * CVE-2026-46520 * CVE-2026-46521 * CVE-2026-46522 * CVE-2026-46523 * CVE-2026-46557 * CVE-2026-46559 * CVE-2026-46692 * CVE-2026-46693 * CVE-2026-47165 * CVE-2026-47166 * CVE-2026-48734 * CVE-2026-48994 * CVE-2026-49218 * CVE-2026-53460 * CVE-2026-53461 * CVE-2026-53463 * CVE-2026-53464 * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56374 * CVE-2026-56376 * CVE-2026-56379 CVSS scores: * CVE-2026-40169 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40169 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42050 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42050 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42326 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42326 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-42326 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45031 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-45031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45031 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45358 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45358 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-45358 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45359 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45359 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-45359 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-45624 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45624 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45624 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-45664 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-45664 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45664 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45664 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46520 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46520 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46520 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46521 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46521 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46521 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46522 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46522 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46523 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46523 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46557 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46557 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46559 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46559 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-46559 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46692 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46692 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46692 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46693 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-46693 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-46693 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-47165 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47165 ( NVD ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-47166 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-47166 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-48734 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48734 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48734 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48994 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-48994 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-49218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53460 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53460 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53461 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53461 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53463 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53463 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-53464 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53464 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53464 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56374 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 41 vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-42050: stack buffer overflow in XTileImage (bsc#1265048). * CVE-2026-42326: information disclosure via malicious IPTC input file (bsc#1268092). * CVE-2026-45031: denial of Service due to resource policy bypass in PSD decoder (bsc#1268094). * CVE-2026-45358: off by one in the meta encoder could result in an out of bounds read of a single byte in the meta encoder (bsc#1268102). * CVE-2026-45359: information Disclosure via Invalid Connected-Components Value (bsc#1268095). * CVE-2026-45624: data exposure due to image processing vulnerability (bsc#1268096). * CVE-2026-45664: denial of Service due to excessive resource use in MNG coder (bsc#1268101). * CVE-2026-46520: denial of Service via out-of-bounds write when processing multiple images (bsc#1268112). * CVE-2026-46521: out of bounds write can occur due to a missing check when using LZMA compression in the MIFF encoder (bsc#1268124). * CVE-2026-46522: denial of service via crafted MIFF file due to a missing check in the MIFF decoder (bsc#1268126). * CVE-2026-46523: heap-use-after-free via a crafted MSL image (bsc#1268125). * CVE-2026-46557: stack overflow can occur in the fx operation by passing a crafted argument due to a missing depth check (bsc#1268123). * CVE-2026-46559: heap buffer over-write of a single byte when specifying certain options due to n incorrect check in the JP2 (bsc#1268121). * CVE-2026-46692: heap buffer over-write in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268120). * CVE-2026-46693: file descriptor hijacking in the server process when a race condition is met via an attacker who can connect to a magick -distribute- cache service (bsc#1268117). * CVE-2026-47165: distributed pixel cache was originally designed to operate without a challenge--response authentication model (bsc#1268114). * CVE-2026-47166: heap buffer over-read in the server process via an attacker who can connect to a magick -distribute- cache service (bsc#1268113). * CVE-2026-48734: Stack Overflow in MVG decoder (bsc#1268122). * CVE-2026-48994: heap buffer over-write due to a missing check of a return value in the MAT decoder on 32-bit systems (bsc#1268111). * CVE-2026-49218: denial of service due to a missing check in the DCM decoder (bsc#1268110). * CVE-2026-53460: out-of-Memory condition due to a missing check for maximum memory request in AcquireAlignedMemory (bsc#1268108). * CVE-2026-53461: out of bounds heap write due to an incorrect loop in the ICON decoder (bsc#1268107). * CVE-2026-53463: null pointer deference due to passing incorrect arguments in the distort operation (bsc#1268105). * CVE-2026-53464: small memory leak due to providing invalid options to the wand option parser (bsc#1268103). * CVE-2026-53466: heap Buffer Over-Read in XCF decoder due to integer conversion overflow (bsc#1270073). * CVE-2026-53467: information Disclosure in MNG decoder because allocated memory is left unchanged (bsc#1270074). * CVE-2026-55594: stack Overflow in MVG decoder due to missing depth check (bsc#1270077). * CVE-2026-55595: infinite Loop in connected-components when providing invalid arguments (bsc#1270079). * CVE-2026-55597: heap Buffer Over-Write in JP2 encoder when due to incorrect handling of arguments (bsc#1270080). * CVE-2026-56361: off-by-one origin validation in allows out-of-bounds read in morphology processing (bsc#1270001). * CVE-2026-56363: division by Zero in binomial kernel (bsc#1270002). * CVE-2026-56364: memory Leak in LoadOpenCLDeviceBenchmark() when parsing malformed XML (bsc#1270003). * CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path that causes a heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing connected-components:* artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in coders/txt.c when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56374: heap-buffer-overflow in FTXT encoder (bsc#1271099). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3023=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3023=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3023=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * perl-PerlMagick-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1 * libMagick++-devel-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-7.1.1.21-150600.3.73.1 * ImageMagick-debugsource-7.1.1.21-150600.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1 * ImageMagick-devel-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-debugsource-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1 * ImageMagick-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-debuginfo-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-devel-7.1.1.21-150600.3.73.1 * perl-PerlMagick-7.1.1.21-150600.3.73.1 * libMagick++-devel-7.1.1.21-150600.3.73.1 * ImageMagick-extra-7.1.1.21-150600.3.73.1 * ImageMagick-extra-debuginfo-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (x86_64) * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-32bit-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.1.21-150600.3.73.1 * ImageMagick-devel-32bit-7.1.1.21-150600.3.73.1 * libMagick++-devel-32bit-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (noarch) * ImageMagick-doc-7.1.1.21-150600.3.73.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libMagickCore-7_Q16HDRI10-64bit-7.1.1.21-150600.3.73.1 * ImageMagick-devel-64bit-7.1.1.21-150600.3.73.1 * libMagick++-devel-64bit-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-64bit-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.1.21-150600.3.73.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libMagick++-7_Q16HDRI5-7.1.1.21-150600.3.73.1 * perl-PerlMagick-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-websafe-7.1.1.21-150600.3.73.1 * libMagick++-devel-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-SUSE-7.1.1.21-150600.3.73.1 * ImageMagick-7.1.1.21-150600.3.73.1 * ImageMagick-debugsource-7.1.1.21-150600.3.73.1 * perl-PerlMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-open-7.1.1.21-150600.3.73.1 * libMagickWand-7_Q16HDRI10-7.1.1.21-150600.3.73.1 * ImageMagick-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-secure-7.1.1.21-150600.3.73.1 * ImageMagick-config-7-upstream-limited-7.1.1.21-150600.3.73.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.1.21-150600.3.73.1 * ImageMagick-devel-7.1.1.21-150600.3.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40169.html * https://www.suse.com/security/cve/CVE-2026-42050.html * https://www.suse.com/security/cve/CVE-2026-42326.html * https://www.suse.com/security/cve/CVE-2026-45031.html * https://www.suse.com/security/cve/CVE-2026-45358.html * https://www.suse.com/security/cve/CVE-2026-45359.html * https://www.suse.com/security/cve/CVE-2026-45624.html * https://www.suse.com/security/cve/CVE-2026-45664.html * https://www.suse.com/security/cve/CVE-2026-46520.html * https://www.suse.com/security/cve/CVE-2026-46521.html * https://www.suse.com/security/cve/CVE-2026-46522.html * https://www.suse.com/security/cve/CVE-2026-46523.html * https://www.suse.com/security/cve/CVE-2026-46557.html * https://www.suse.com/security/cve/CVE-2026-46559.html * https://www.suse.com/security/cve/CVE-2026-46692.html * https://www.suse.com/security/cve/CVE-2026-46693.html * https://www.suse.com/security/cve/CVE-2026-47165.html * https://www.suse.com/security/cve/CVE-2026-47166.html * https://www.suse.com/security/cve/CVE-2026-48734.html * https://www.suse.com/security/cve/CVE-2026-48994.html * https://www.suse.com/security/cve/CVE-2026-49218.html * https://www.suse.com/security/cve/CVE-2026-53460.html * https://www.suse.com/security/cve/CVE-2026-53461.html * https://www.suse.com/security/cve/CVE-2026-53463.html * https://www.suse.com/security/cve/CVE-2026-53464.html * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56374.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1265048 * https://bugzilla.suse.com/show_bug.cgi?id=1268092 * https://bugzilla.suse.com/show_bug.cgi?id=1268094 * https://bugzilla.suse.com/show_bug.cgi?id=1268095 * https://bugzilla.suse.com/show_bug.cgi?id=1268096 * https://bugzilla.suse.com/show_bug.cgi?id=1268101 * https://bugzilla.suse.com/show_bug.cgi?id=1268102 * https://bugzilla.suse.com/show_bug.cgi?id=1268103 * https://bugzilla.suse.com/show_bug.cgi?id=1268105 * https://bugzilla.suse.com/show_bug.cgi?id=1268107 * https://bugzilla.suse.com/show_bug.cgi?id=1268108 * https://bugzilla.suse.com/show_bug.cgi?id=1268110 * https://bugzilla.suse.com/show_bug.cgi?id=1268111 * https://bugzilla.suse.com/show_bug.cgi?id=1268112 * https://bugzilla.suse.com/show_bug.cgi?id=1268113 * https://bugzilla.suse.com/show_bug.cgi?id=1268114 * https://bugzilla.suse.com/show_bug.cgi?id=1268117 * https://bugzilla.suse.com/show_bug.cgi?id=1268120 * https://bugzilla.suse.com/show_bug.cgi?id=1268121 * https://bugzilla.suse.com/show_bug.cgi?id=1268122 * https://bugzilla.suse.com/show_bug.cgi?id=1268123 * https://bugzilla.suse.com/show_bug.cgi?id=1268124 * https://bugzilla.suse.com/show_bug.cgi?id=1268125 * https://bugzilla.suse.com/show_bug.cgi?id=1268126 * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 * https://bugzilla.suse.com/show_bug.cgi?id=1271099 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:39:22 -0000 Subject: SUSE-SU-2026:3022-1: important: Security update for sccache Message-ID: <178413356262.13854.4765342288287475577@fcb35a5fe5ab> # Security update for sccache Announcement ID: SUSE-SU-2026:3022-1 Release Date: 2026-07-15T09:48:48Z Rating: important References: * bsc#1210346 * bsc#1223238 * bsc#1229955 * bsc#1242611 * bsc#1243868 * bsc#1257923 * bsc#1270206 * bsc#1270512 * bsc#1270559 * bsc#1270693 * bsc#1270736 * bsc#1270869 * bsc#1270938 * bsc#1270948 Cross-References: * CVE-2023-26964 * CVE-2024-12224 * CVE-2024-32650 * CVE-2024-43806 * CVE-2025-3416 * CVE-2026-25727 * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2023-26964 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-26964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-26964 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-12224 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2024-12224 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2024-12224 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2024-32650 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-43806 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-3416 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-3416 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-3416 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 14 vulnerabilities can now be installed. ## Description: This update for sccache fixes the following issues: Update to version 0.15.0~17. * CVE-2023-26964: hyper,h2: high resource consumption due to stream stacking when H2 component processes `HTTP2 RST_STREAM` frames (bsc#1210346). * CVE-2024-32650: rust-rustls: infinite loop in `rustls::conn::ConnectionCommon:complete_io()` when processing client input network input (bsc#1223238). * CVE-2025-3416: openssl: use-after-free in `Md::fetch` and `Cipher::fetch` (bsc#1242611). * CVE-2026-25727: time: stack exhaustion in the RFC 2822 date parser when processing certain user provided input (bsc#1257923). * CVE-2026-41676: openssl: short buffer overflow via `Deriver:derive` and `PkeyCtxRef:derive` when using OpenSSL 1.1.1 (bsc#1270206). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270559). * CVE-2026-41678: openssl: OOB write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270693). * CVE-2026-41681: openssl: stack corruption due to `MdCtxRef::digest_final()` writing past caller buffer with no length check (bsc#1270736). * CVE-2026-41898: openssl: information leak to network peers due to unchecked callback-returned length in PSK and cookie generate trampolines (bsc#1270869). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` when processing certificates with non-UTF-8 OCSP URLs (bsc#1270512). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding (bsc#1270938). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers (bsc#1270948). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3022=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3022=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3022=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3022=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-debugsource-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * sccache-debuginfo-0.16.0~0-150600.10.11.1 * sccache-0.16.0~0-150600.10.11.1 ## References: * https://www.suse.com/security/cve/CVE-2023-26964.html * https://www.suse.com/security/cve/CVE-2024-12224.html * https://www.suse.com/security/cve/CVE-2024-32650.html * https://www.suse.com/security/cve/CVE-2024-43806.html * https://www.suse.com/security/cve/CVE-2025-3416.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1210346 * https://bugzilla.suse.com/show_bug.cgi?id=1223238 * https://bugzilla.suse.com/show_bug.cgi?id=1229955 * https://bugzilla.suse.com/show_bug.cgi?id=1242611 * https://bugzilla.suse.com/show_bug.cgi?id=1243868 * https://bugzilla.suse.com/show_bug.cgi?id=1257923 * https://bugzilla.suse.com/show_bug.cgi?id=1270206 * https://bugzilla.suse.com/show_bug.cgi?id=1270512 * https://bugzilla.suse.com/show_bug.cgi?id=1270559 * https://bugzilla.suse.com/show_bug.cgi?id=1270693 * https://bugzilla.suse.com/show_bug.cgi?id=1270736 * https://bugzilla.suse.com/show_bug.cgi?id=1270869 * https://bugzilla.suse.com/show_bug.cgi?id=1270938 * https://bugzilla.suse.com/show_bug.cgi?id=1270948 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 16:39:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 16:39:30 -0000 Subject: SUSE-SU-2026:3021-1: important: Security update for uriparser Message-ID: <178413357093.13854.1275781530135943900@fcb35a5fe5ab> # Security update for uriparser Announcement ID: SUSE-SU-2026:3021-1 Release Date: 2026-07-15T09:48:32Z Rating: important References: * bsc#1262999 * bsc#1264578 * bsc#1264579 Cross-References: * CVE-2026-42371 * CVE-2026-44927 * CVE-2026-44928 CVSS scores: * CVE-2026-42371 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42371 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44927 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-44927 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-44927 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44927 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for uriparser fixes the following issues * CVE-2026-42371: numeric truncation in text range comparison when an application accepts URIs with a length in gigabytes (bsc#1262999). * CVE-2026-44927: truncation of `ptrdiff_t` to `int` in various places (bsc#1264578). * CVE-2026-44928: function family `EqualsUri` can misclassify two unequal URIs as equal (bsc#1264579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3021=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * liburiparser1-0.8.5-150000.3.14.1 * uriparser-0.8.5-150000.3.14.1 * uriparser-devel-0.8.5-150000.3.14.1 * liburiparser1-debuginfo-0.8.5-150000.3.14.1 * uriparser-debugsource-0.8.5-150000.3.14.1 * uriparser-debuginfo-0.8.5-150000.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42371.html * https://www.suse.com/security/cve/CVE-2026-44927.html * https://www.suse.com/security/cve/CVE-2026-44928.html * https://bugzilla.suse.com/show_bug.cgi?id=1262999 * https://bugzilla.suse.com/show_bug.cgi?id=1264578 * https://bugzilla.suse.com/show_bug.cgi?id=1264579 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:30:04 -0000 Subject: SUSE-SU-2026:3064-1: important: Security update for docker Message-ID: <178414740467.406.5690913361549692592@1437f03ce14a> # Security update for docker Announcement ID: SUSE-SU-2026:3064-1 Release Date: 2026-07-15T15:02:51Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for docker rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3064=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3064=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3064=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3064=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3064=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3064=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3064=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3064=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3064=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3064=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3064=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3064=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3064=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3064=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3064=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3064=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3064=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * docker-zsh-completion-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * Containers Module 15-SP7 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * docker-zsh-completion-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * docker-29.4.0_ce-150000.255.1 * docker-buildx-0.33.0-150000.255.1 * docker-debuginfo-29.4.0_ce-150000.255.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * docker-bash-completion-29.4.0_ce-150000.255.1 * docker-rootless-extras-29.4.0_ce-150000.255.1 * docker-zsh-completion-29.4.0_ce-150000.255.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:30:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:30:08 -0000 Subject: SUSE-SU-2026:3063-1: important: Security update for buildah Message-ID: <178414740882.406.8359852495176483118@1437f03ce14a> # Security update for buildah Announcement ID: SUSE-SU-2026:3063-1 Release Date: 2026-07-15T15:01:02Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for buildah rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3063=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3063=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3063=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3063=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3063=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3063=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3063=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3063=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * buildah-1.35.5-150500.3.64.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * buildah-1.35.5-150500.3.64.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * buildah-1.35.5-150500.3.64.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:31:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:31:19 -0000 Subject: SUSE-SU-2026:3059-1: important: Security update for python-aiohttp Message-ID: <178414747935.406.12702331336998101759@1437f03ce14a> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:3059-1 Release Date: 2026-07-15T13:34:43Z Rating: important References: * bsc#1261320 * bsc#1261321 * bsc#1261322 * bsc#1261329 * bsc#1261331 * bsc#1261332 * bsc#1261334 * bsc#1261335 * bsc#1261343 * bsc#1267471 * bsc#1267561 Cross-References: * CVE-2026-22815 * CVE-2026-34513 * CVE-2026-34514 * CVE-2026-34516 * CVE-2026-34517 * CVE-2026-34518 * CVE-2026-34519 * CVE-2026-34520 * CVE-2026-34525 * CVE-2026-34993 * CVE-2026-47265 CVSS scores: * CVE-2026-22815 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22815 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22815 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-22815 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34513 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34513 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34513 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34513 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34514 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-34514 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-34514 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34514 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34516 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34516 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34516 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34516 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34517 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34517 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34517 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34517 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-34518 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34518 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34518 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34518 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-34519 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34519 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34519 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34519 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34520 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34520 ( NVD ): 2.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34520 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-34525 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-34525 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-34525 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-34525 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-34993 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L * CVE-2026-34993 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-34993 ( NVD ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H * CVE-2026-47265 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-47265 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47265 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues * CVE-2026-22815: insufficient header/trailer handling can cause a denial of service (bsc#1261320). * CVE-2026-34513: unbounded DNS cache can cause a denial of service (bsc#1261321). * CVE-2026-34514: content_type parameter manipulation can lead to header Injection (bsc#1261322). * CVE-2026-34516: excessive multipart headers can cause a denial of service (bsc#1261329). * CVE-2026-34517: large multipart form fields can cause a denial of service (bsc#1261331). * CVE-2026-34518: retained Cookie and Proxy-Authorization headers during redirects can lead to information disclosure (bsc#1261332). * CVE-2026-34519: reason parameter can be use to perform header injection (bsc#1261334). * CVE-2026-34520: improper character handling can lead to header injection (bsc#1261335). * CVE-2026-34525: multiple Host headers can potentially lead to security bypass (bsc#1261343). * CVE-2026-34993: arbitrary code execution via loading untrusted input in CookieJar.load() (bsc#1267471). * CVE-2026-47265: cookies set with the `cookies` parameter on requests are sent after following a cross-origin redirect (bsc#1267561). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3059=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3059=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3059=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3059=1 ## Package List: * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-aiohttp-3.6.0-150100.3.35.1 * python-aiohttp-debugsource-3.6.0-150100.3.35.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-22815.html * https://www.suse.com/security/cve/CVE-2026-34513.html * https://www.suse.com/security/cve/CVE-2026-34514.html * https://www.suse.com/security/cve/CVE-2026-34516.html * https://www.suse.com/security/cve/CVE-2026-34517.html * https://www.suse.com/security/cve/CVE-2026-34518.html * https://www.suse.com/security/cve/CVE-2026-34519.html * https://www.suse.com/security/cve/CVE-2026-34520.html * https://www.suse.com/security/cve/CVE-2026-34525.html * https://www.suse.com/security/cve/CVE-2026-34993.html * https://www.suse.com/security/cve/CVE-2026-47265.html * https://bugzilla.suse.com/show_bug.cgi?id=1261320 * https://bugzilla.suse.com/show_bug.cgi?id=1261321 * https://bugzilla.suse.com/show_bug.cgi?id=1261322 * https://bugzilla.suse.com/show_bug.cgi?id=1261329 * https://bugzilla.suse.com/show_bug.cgi?id=1261331 * https://bugzilla.suse.com/show_bug.cgi?id=1261332 * https://bugzilla.suse.com/show_bug.cgi?id=1261334 * https://bugzilla.suse.com/show_bug.cgi?id=1261335 * https://bugzilla.suse.com/show_bug.cgi?id=1261343 * https://bugzilla.suse.com/show_bug.cgi?id=1267471 * https://bugzilla.suse.com/show_bug.cgi?id=1267561 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:31:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:31:33 -0000 Subject: SUSE-SU-2026:3058-1: important: Security update for gstreamer-plugins-bad Message-ID: <178414749323.406.17863182349073152151@1437f03ce14a> # Security update for gstreamer-plugins-bad Announcement ID: SUSE-SU-2026:3058-1 Release Date: 2026-07-15T13:32:28Z Rating: important References: * bsc#1268168 * bsc#1268406 * bsc#1268408 * bsc#1268410 * bsc#1268971 * bsc#1271051 * bsc#1271168 Cross-References: * CVE-2026-12892 * CVE-2026-14935 * CVE-2026-52720 * CVE-2026-52721 * CVE-2026-52722 * CVE-2026-53702 * CVE-2026-59692 CVSS scores: * CVE-2026-12892 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12892 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12892 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-14935 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-14935 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-14935 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-52720 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52720 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-52721 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-52721 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-52722 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-53702 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-53702 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for gstreamer-plugins-bad fixes the following issues * CVE-2026-12892: 1-byte heap out-of-bounds read in H.264 NAL extension slice parser (bsc#1268971). * CVE-2026-14935: webrtcbin accepts remote SDP without a=fingerprint due to inverted presence check (bsc#1271051). * CVE-2026-52720: invalid check of total area instead of individual dimensions could trigger a heap out-of-bounds write (bsc#1268406). * CVE-2026-52721: crafted PCAP records during IPv4 or TCP header parsing could cause an out-of-bounds read (bsc#1268408). * CVE-2026-52722: crafted VMnc stream with large cursor dimensions can overflow signed integer (bsc#1268410). * CVE-2026-53702: incorrect loop bound during H.265 SEI message parsing could result in a stack buffer overflow (bsc#1268168). * CVE-2026-59692: unvalidated peer certificate Subject DN printed during a DTLS handshake could cause a stack buffer overflow (bsc#1271168). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3058=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3058=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3058=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3058=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3058=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3058=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-transcoder-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstVulkanXCB-1_0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstTranscoder-1_0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-transcoder-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-debuginfo-1.24.0-150600.4.9.1 * gstreamer-transcoder-devel-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstVulkanWayland-1_0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstVulkan-1_0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libgstwayland-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-64bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-64bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-64bit-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstva-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstmse-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplay-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-64bit-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstplay-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-64bit-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-64bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstmse-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-64bit-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-64bit-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-64bit-debuginfo-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (x86_64) * libgstwayland-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-32bit-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmse-1_0-0-32bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-32bit-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-32bit-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-32bit-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstva-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstplay-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-32bit-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-32bit-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstmse-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-chromaprint-32bit-1.24.0-150600.4.9.1 * libgstva-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-32bit-debuginfo-1.24.0-150600.4.9.1 * openSUSE Leap 15.6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * Desktop Applications Module 15-SP7 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libgstmse-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstPlay-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstVa-1_0-1.24.0-150600.4.9.1 * typelib-1_0-CudaGst-1_0-1.24.0-150600.4.9.1 * libgstisoff-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCodecs-1_0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstplay-1_0-0-1.24.0-150600.4.9.1 * libgstcuda-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstBadAudio-1_0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstMpegts-1_0-1.24.0-150600.4.9.1 * typelib-1_0-GstWebRTC-1_0-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstInsertBin-1_0-1.24.0-150600.4.9.1 * libgstcodecparsers-1_0-0-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-1.24.0-150600.4.9.1 * libgstmse-1_0-0-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-1.24.0-150600.4.9.1 * libgstmpegts-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstPlayer-1_0-1.24.0-150600.4.9.1 * libgstphotography-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstMse-1_0-1.24.0-150600.4.9.1 * libgstva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstinsertbin-1_0-0-1.24.0-150600.4.9.1 * libgstplay-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstva-1_0-0-1.24.0-150600.4.9.1 * typelib-1_0-GstCuda-1_0-1.24.0-150600.4.9.1 * libgstwayland-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-devel-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * libgstanalytics-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-1.24.0-150600.4.9.1 * libgsturidownloader-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstadaptivedemux-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstAnalytics-1_0-1.24.0-150600.4.9.1 * libgstwebrtcnice-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-1.24.0-150600.4.9.1 * libgstplayer-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstbadaudio-1_0-0-1.24.0-150600.4.9.1 * libgstvulkan-1_0-0-1.24.0-150600.4.9.1 * libgstcodecs-1_0-0-1.24.0-150600.4.9.1 * libgstbasecamerabinsrc-1_0-0-1.24.0-150600.4.9.1 * libgstdxva-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstsctp-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgstwebrtc-1_0-0-debuginfo-1.24.0-150600.4.9.1 * typelib-1_0-GstDxva-1_0-1.24.0-150600.4.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gstreamer-plugins-bad-lang-1.24.0-150600.4.9.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libgsttranscoder-1_0-0-debuginfo-1.24.0-150600.4.9.1 * libgsttranscoder-1_0-0-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debuginfo-1.24.0-150600.4.9.1 * gstreamer-plugins-bad-debugsource-1.24.0-150600.4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12892.html * https://www.suse.com/security/cve/CVE-2026-14935.html * https://www.suse.com/security/cve/CVE-2026-52720.html * https://www.suse.com/security/cve/CVE-2026-52721.html * https://www.suse.com/security/cve/CVE-2026-52722.html * https://www.suse.com/security/cve/CVE-2026-53702.html * https://www.suse.com/security/cve/CVE-2026-59692.html * https://bugzilla.suse.com/show_bug.cgi?id=1268168 * https://bugzilla.suse.com/show_bug.cgi?id=1268406 * https://bugzilla.suse.com/show_bug.cgi?id=1268408 * https://bugzilla.suse.com/show_bug.cgi?id=1268410 * https://bugzilla.suse.com/show_bug.cgi?id=1268971 * https://bugzilla.suse.com/show_bug.cgi?id=1271051 * https://bugzilla.suse.com/show_bug.cgi?id=1271168 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:31:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:31:51 -0000 Subject: SUSE-SU-2026:3057-1: important: Security update for terraform-provider-susepubliccloud Message-ID: <178414751119.406.16326906739108859705@1437f03ce14a> # Security update for terraform-provider-susepubliccloud Announcement ID: SUSE-SU-2026:3057-1 Release Date: 2026-07-15T13:30:14Z Rating: important References: * bsc#1208300 * bsc#1260180 * bsc#1263247 * bsc#1263316 * bsc#1263357 * bsc#1263411 * bsc#1263445 * bsc#1263515 * bsc#1263606 * bsc#1266477 Cross-References: * CVE-2022-41723 * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-41602 * CVE-2026-41603 * CVE-2026-41604 * CVE-2026-41605 * CVE-2026-41606 * CVE-2026-41607 * CVE-2026-41636 CVSS scores: * CVE-2022-41723 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41603 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41603 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-41604 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41604 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41605 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41605 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41636 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41636 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41636 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41636 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for terraform-provider-susepubliccloud fixes the following issues * CVE-2022-41723: go1.19,go1.20: net/http2: quadratic complexity in HPACK decoding (bsc#1208300). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 `:path` pseudo-header (bsc#1260180). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477). * CVE-2026-41602: github.com/apache/thrift: `TFramedTransport` frame size headers can lead to a `uint32` integer overflow (bsc#1263515). * CVE-2026-41603: github.com/apache/thrift: improper hostname verification in `TSSLTransportFactory` can lead to host mismatch (bsc#1263606). * CVE-2026-41604: github.com/apache/thrift: swift input with an invalid field range can lead to an out-of-bounds read and application crash (bsc#1263445). * CVE-2026-41605: github.com/apache/thrift: compact protocol messages with large integer values can lead to integer overflow (bsc#1263411). * CVE-2026-41606: github.com/apache/thrift: crafted nested messages in `c_glib` dispatch can lead to uncontrolled recursion and denial of service (bsc#1263357). * CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263316). * CVE-2026-41636: github.com/apache/thrift: uncontrolled recursion in Node.js bindings can lead to denial of service via stack exhaustion (bsc#1263247). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3057=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3057=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.14.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2022-41723.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-41603.html * https://www.suse.com/security/cve/CVE-2026-41604.html * https://www.suse.com/security/cve/CVE-2026-41605.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-41607.html * https://www.suse.com/security/cve/CVE-2026-41636.html * https://bugzilla.suse.com/show_bug.cgi?id=1208300 * https://bugzilla.suse.com/show_bug.cgi?id=1260180 * https://bugzilla.suse.com/show_bug.cgi?id=1263247 * https://bugzilla.suse.com/show_bug.cgi?id=1263316 * https://bugzilla.suse.com/show_bug.cgi?id=1263357 * https://bugzilla.suse.com/show_bug.cgi?id=1263411 * https://bugzilla.suse.com/show_bug.cgi?id=1263445 * https://bugzilla.suse.com/show_bug.cgi?id=1263515 * https://bugzilla.suse.com/show_bug.cgi?id=1263606 * https://bugzilla.suse.com/show_bug.cgi?id=1266477 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:32:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:32:53 -0000 Subject: SUSE-SU-2026:3056-1: important: Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Message-ID: <178414757334.406.9196729659700463782@1437f03ce14a> # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:3056-1 Release Date: 2026-07-15T13:28:53Z Rating: important References: * bsc#1208300 * bsc#1241030 * bsc#1241033 * bsc#1241728 * bsc#1251365 * bsc#1251559 * bsc#1253508 * bsc#1253517 * bsc#1253797 * bsc#1253799 * bsc#1253980 * bsc#1253983 * bsc#1258096 * bsc#1260139 * bsc#1260149 * bsc#1260180 * bsc#1263247 * bsc#1263313 * bsc#1263357 * bsc#1263411 * bsc#1263445 * bsc#1263515 * bsc#1263606 * bsc#1264862 * bsc#1264888 * bsc#1264938 * bsc#1266051 * bsc#1266057 * bsc#1266086 * bsc#1266112 * bsc#1266122 * bsc#1266127 * bsc#1266132 * bsc#1266150 * bsc#1266160 * bsc#1266477 * bsc#1266482 * bsc#1266541 * bsc#1266547 * bsc#1267058 * bsc#1267271 * bsc#1267273 * bsc#1267276 Cross-References: * CVE-2022-41723 * CVE-2025-22872 * CVE-2025-32386 * CVE-2025-32387 * CVE-2025-47911 * CVE-2025-47913 * CVE-2025-47914 * CVE-2025-58181 * CVE-2025-58190 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-25934 * CVE-2026-27136 * CVE-2026-33186 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41506 * CVE-2026-41602 * CVE-2026-41603 * CVE-2026-41604 * CVE-2026-41605 * CVE-2026-41606 * CVE-2026-41607 * CVE-2026-41636 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-44740 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2022-41723 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-41723 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-22872 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2025-22872 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-22872 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L * CVE-2025-32386 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32386 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32386 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32387 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-32387 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-32387 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-47911 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47911 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47911 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47913 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-47913 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47913 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-47914 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-47914 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-47914 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58181 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58181 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58181 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58190 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58190 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25934 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25934 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25934 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25934 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-41506 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-41506 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-41602 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41602 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41602 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41603 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41603 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-41603 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-41604 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41604 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41604 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-41605 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41605 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-41605 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41636 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41636 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41636 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41636 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44740 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44740 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44740 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 39 vulnerabilities and has four security fixes can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider- null, terraform-provider-random, terraform-provider-tls fixes the following issues * CVE-2022-41723: go1.19,go1.20: net/http2: quadratic complexity in HPACK decoding (bsc#1208300). * CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241728). * CVE-2025-32386: helm: specially crafted chart archive can cause OOM termination (bsc#1241030). * CVE-2025-32387: helm: specially crafted JSON schema can cause a stack overflow (bsc#1241033). * CVE-2025-47911: golang.org/x/net/html: various algorithms have quadratic complexity when parsing HTML documents (bsc#1251365). * CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253508 bsc#1253517). * CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1253980 bsc#1253983). * CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253797 bsc#1253799). * CVE-2025-58190: golang.org/x/net/html: specially crafted input can cause excessive memory consumption by `html.ParseFragment` (bsc#1251559). * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: golang.org/x/net/html: multiple issues when parsing HTML files (bsc#1267058). * CVE-2026-25934: github.com/go-git/go-git/v5: improper verification of data integrity values for `.pack` and `.idx` files can lead to the consumption of corrupted files (bsc#1258096). * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 `:path` pseudo-header (bsc#1260139 bsc#1260149 bsc#1260180). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266477 bsc#1266482 bsc#1266541 bsc#1266547). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833, CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues in the crypto/ssh library (bsc#1266051 bsc#1266057 bsc#1266086 bsc#1266112 bsc#1266122 bsc#1266127 bsc#1266132 bsc#1266150 bsc#1266160). * CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264862 bsc#1264888 bsc#1264938). * CVE-2026-41602: github.com/apache/thrift: `TFramedTransport` frame size headers can lead to a `uint32` integer overflow (bsc#1263515). * CVE-2026-41603: github.com/apache/thrift: improper hostname verification in `TSSLTransportFactory` can lead to host mismatch (bsc#1263606). * CVE-2026-41604: github.com/apache/thrift: swift input with an invalid field range can lead to an out-of-bounds read and application crash (bsc#1263445). * CVE-2026-41605: github.com/apache/thrift: compact protocol messages with large integer values can lead to integer overflow (bsc#1263411). * CVE-2026-41606: github.com/apache/thrift: crafted nested messages in `c_glib` dispatch can lead to uncontrolled recursion and denial of service (bsc#1263357). * CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263313). * CVE-2026-41636: github.com/apache/thrift: uncontrolled recursion in Node.js bindings can lead to denial of service via stack exhaustion (bsc#1263247). * CVE-2026-44740: github.com/go-git/go-billy/v5: improper input handling in many components can lead to DoS via infinite loops, panics or resource consumption (bsc#1267271 bsc#1267273 bsc#1267276). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3056=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3056=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.18.1 * terraform-provider-external-2.0.0-150200.6.12.1 * terraform-provider-random-3.0.0-150200.6.15.1 * terraform-provider-tls-3.0.0-150200.5.15.1 * terraform-provider-local-2.0.0-150200.6.17.1 * terraform-provider-helm-2.9.0-150200.6.23.1 * terraform-provider-google-3.43.0-150200.6.12.1 * terraform-provider-null-3.0.0-150200.6.18.1 * terraform-provider-azurerm-2.32.0-150200.6.12.1 * terraform-provider-kubernetes-1.13.2-150200.6.12.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.18.1 * terraform-provider-external-2.0.0-150200.6.12.1 * terraform-provider-tls-3.0.0-150200.5.15.1 * terraform-provider-random-3.0.0-150200.6.15.1 * terraform-provider-helm-2.9.0-150200.6.23.1 * terraform-provider-local-2.0.0-150200.6.17.1 * terraform-provider-google-3.43.0-150200.6.12.1 * terraform-provider-null-3.0.0-150200.6.18.1 * terraform-provider-azurerm-2.32.0-150200.6.12.1 * terraform-provider-kubernetes-1.13.2-150200.6.12.1 ## References: * https://www.suse.com/security/cve/CVE-2022-41723.html * https://www.suse.com/security/cve/CVE-2025-22872.html * https://www.suse.com/security/cve/CVE-2025-32386.html * https://www.suse.com/security/cve/CVE-2025-32387.html * https://www.suse.com/security/cve/CVE-2025-47911.html * https://www.suse.com/security/cve/CVE-2025-47913.html * https://www.suse.com/security/cve/CVE-2025-47914.html * https://www.suse.com/security/cve/CVE-2025-58181.html * https://www.suse.com/security/cve/CVE-2025-58190.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-25934.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41506.html * https://www.suse.com/security/cve/CVE-2026-41602.html * https://www.suse.com/security/cve/CVE-2026-41603.html * https://www.suse.com/security/cve/CVE-2026-41604.html * https://www.suse.com/security/cve/CVE-2026-41605.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-41607.html * https://www.suse.com/security/cve/CVE-2026-41636.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-44740.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1208300 * https://bugzilla.suse.com/show_bug.cgi?id=1241030 * https://bugzilla.suse.com/show_bug.cgi?id=1241033 * https://bugzilla.suse.com/show_bug.cgi?id=1241728 * https://bugzilla.suse.com/show_bug.cgi?id=1251365 * https://bugzilla.suse.com/show_bug.cgi?id=1251559 * https://bugzilla.suse.com/show_bug.cgi?id=1253508 * https://bugzilla.suse.com/show_bug.cgi?id=1253517 * https://bugzilla.suse.com/show_bug.cgi?id=1253797 * https://bugzilla.suse.com/show_bug.cgi?id=1253799 * https://bugzilla.suse.com/show_bug.cgi?id=1253980 * https://bugzilla.suse.com/show_bug.cgi?id=1253983 * https://bugzilla.suse.com/show_bug.cgi?id=1258096 * https://bugzilla.suse.com/show_bug.cgi?id=1260139 * https://bugzilla.suse.com/show_bug.cgi?id=1260149 * https://bugzilla.suse.com/show_bug.cgi?id=1260180 * https://bugzilla.suse.com/show_bug.cgi?id=1263247 * https://bugzilla.suse.com/show_bug.cgi?id=1263313 * https://bugzilla.suse.com/show_bug.cgi?id=1263357 * https://bugzilla.suse.com/show_bug.cgi?id=1263411 * https://bugzilla.suse.com/show_bug.cgi?id=1263445 * https://bugzilla.suse.com/show_bug.cgi?id=1263515 * https://bugzilla.suse.com/show_bug.cgi?id=1263606 * https://bugzilla.suse.com/show_bug.cgi?id=1264862 * https://bugzilla.suse.com/show_bug.cgi?id=1264888 * https://bugzilla.suse.com/show_bug.cgi?id=1264938 * https://bugzilla.suse.com/show_bug.cgi?id=1266051 * https://bugzilla.suse.com/show_bug.cgi?id=1266057 * https://bugzilla.suse.com/show_bug.cgi?id=1266086 * https://bugzilla.suse.com/show_bug.cgi?id=1266112 * https://bugzilla.suse.com/show_bug.cgi?id=1266122 * https://bugzilla.suse.com/show_bug.cgi?id=1266127 * https://bugzilla.suse.com/show_bug.cgi?id=1266132 * https://bugzilla.suse.com/show_bug.cgi?id=1266150 * https://bugzilla.suse.com/show_bug.cgi?id=1266160 * https://bugzilla.suse.com/show_bug.cgi?id=1266477 * https://bugzilla.suse.com/show_bug.cgi?id=1266482 * https://bugzilla.suse.com/show_bug.cgi?id=1266541 * https://bugzilla.suse.com/show_bug.cgi?id=1266547 * https://bugzilla.suse.com/show_bug.cgi?id=1267058 * https://bugzilla.suse.com/show_bug.cgi?id=1267271 * https://bugzilla.suse.com/show_bug.cgi?id=1267273 * https://bugzilla.suse.com/show_bug.cgi?id=1267276 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:32:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:32:59 -0000 Subject: SUSE-SU-2026:3055-1: important: Security update for radvd Message-ID: <178414757902.406.8103912748294183490@1437f03ce14a> # Security update for radvd Announcement ID: SUSE-SU-2026:3055-1 Release Date: 2026-07-15T13:23:58Z Rating: important References: * bsc#1268641 Cross-References: * CVE-2026-48715 CVSS scores: * CVE-2026-48715 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48715 ( NVD ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-48715 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for radvd fixes the following issue * CVE-2026-48715: stack-based buffer overflow in the `radvdump` Route Information option parser when processing crafted ICMPv6 Router Advertisements (bsc#1268641). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3055=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3055=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3055=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3055=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3055=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3055=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3055=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3055=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3055=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3055=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3055=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * radvd-debuginfo-2.17-150000.5.8.1 * radvd-2.17-150000.5.8.1 * radvd-debugsource-2.17-150000.5.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48715.html * https://bugzilla.suse.com/show_bug.cgi?id=1268641 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:06 -0000 Subject: SUSE-SU-2026:3054-1: important: Security update for tiff Message-ID: <178414758613.406.12745672128197655721@1437f03ce14a> # Security update for tiff Announcement ID: SUSE-SU-2026:3054-1 Release Date: 2026-07-15T13:21:52Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3054=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3054=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3054=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3054=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3054=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3054=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3054=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3054=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3054=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3054=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3054=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3054=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3054=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3054=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libtiff5-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libtiff5-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libtiff5-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * Basesystem Module 15-SP7 (x86_64) * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 * libtiff5-32bit-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * tiff-debuginfo-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * tiff-debuginfo-4.0.9-150000.45.69.1 * libtiff5-debuginfo-4.0.9-150000.45.69.1 * tiff-debugsource-4.0.9-150000.45.69.1 * libtiff5-4.0.9-150000.45.69.1 * libtiff-devel-4.0.9-150000.45.69.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libtiff5-32bit-4.0.9-150000.45.69.1 * libtiff5-32bit-debuginfo-4.0.9-150000.45.69.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:33 -0000 Subject: SUSE-SU-2026:3053-1: important: Security update for ImageMagick Message-ID: <178414761303.406.5365684674813797272@1437f03ce14a> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:3053-1 Release Date: 2026-07-15T13:18:11Z Rating: important References: * bsc#1268640 * bsc#1268645 * bsc#1268878 * bsc#1268879 * bsc#1268880 * bsc#1269063 * bsc#1269064 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270004 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 Cross-References: * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56365 * CVE-2026-56367 * CVE-2026-56368 * CVE-2026-56370 * CVE-2026-56371 * CVE-2026-56376 * CVE-2026-56379 CVSS scores: * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56365 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56365 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56365 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56367 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-56367 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56367 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56367 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-56368 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56368 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56368 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56368 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56368 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56370 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56370 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56370 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56370 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56371 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56371 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56371 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56376 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56376 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56376 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56376 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 15 vulnerabilities and has one security fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). * CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). * CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). * CVE-2026-56365: memory leak in PNG encoder when writing a MNG image (bsc#1270004). * CVE-2026-56367: integer overflow in the PSB (PSD v2) RLE decoding path can lead to an heap out-of-bounds read (bsc#1268645). * CVE-2026-56368: improper memory management can lead to memory leak in multiple coders that write raw pixel data (bsc#1269064). * CVE-2026-56370: out-of-bounds access in `ConnectedComponentsImage()` when processing `connected-components:*` artifacts with invalid indices (bsc#1269063). * CVE-2026-56371: memory leak in `coders/txt.c` when processing TXT files with texture attributes (bsc#1268879). * CVE-2026-56376: heap use-after-free in the meta coder can lead to denial of service via specially crafted image files (bsc#1268880). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3053=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3053=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3053=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3053=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3053=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3053=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3053=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3053=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3053=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3053=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3053=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3053=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-extra-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.96.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.96.1 * libMagick++-devel-64bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (x86_64) * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.96.1 * libMagick++-devel-32bit-7.1.0.9-150400.6.96.1 * ImageMagick-devel-32bit-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.96.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * ImageMagick-devel-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.96.1 * ImageMagick-7.1.0.9-150400.6.96.1 * libMagick++-devel-7.1.0.9-150400.6.96.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.96.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.96.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * perl-PerlMagick-7.1.0.9-150400.6.96.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.96.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * ImageMagick-debuginfo-7.1.0.9-150400.6.96.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.96.1 * ImageMagick-debugsource-7.1.0.9-150400.6.96.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56365.html * https://www.suse.com/security/cve/CVE-2026-56367.html * https://www.suse.com/security/cve/CVE-2026-56368.html * https://www.suse.com/security/cve/CVE-2026-56370.html * https://www.suse.com/security/cve/CVE-2026-56371.html * https://www.suse.com/security/cve/CVE-2026-56376.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268645 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1268879 * https://bugzilla.suse.com/show_bug.cgi?id=1268880 * https://bugzilla.suse.com/show_bug.cgi?id=1269063 * https://bugzilla.suse.com/show_bug.cgi?id=1269064 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270004 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:37 -0000 Subject: SUSE-SU-2026:3052-1: important: Security update for containerd Message-ID: <178414761771.406.2940706366262118550@1437f03ce14a> # Security update for containerd Announcement ID: SUSE-SU-2026:3052-1 Release Date: 2026-07-15T13:12:40Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for containerd rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3052=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3052=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3052=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3052=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3052=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3052=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3052=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3052=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3052=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3052=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3052=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3052=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3052=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3052=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3052=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3052=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3052=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * containerd-1.7.29-150000.139.1 * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * containerd-1.7.29-150000.139.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-devel-1.7.29-150000.139.1 * containerd-ctr-1.7.29-150000.139.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * containerd-1.7.29-150000.139.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:41 -0000 Subject: SUSE-SU-2026:3051-1: important: Security update for runc Message-ID: <178414762171.406.5859659546542499449@1437f03ce14a> # Security update for runc Announcement ID: SUSE-SU-2026:3051-1 Release Date: 2026-07-15T13:11:12Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for runc rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3051=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3051=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3051=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3051=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3051=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3051=1 * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-3051=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3051=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3051=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3051=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3051=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3051=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3051=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3051=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3051=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3051=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3051=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * runc-1.3.4-150000.98.1 * runc-debuginfo-1.3.4-150000.98.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:46 -0000 Subject: SUSE-SU-2026:3050-1: important: Security update for helm Message-ID: <178414762694.406.13014237484471235946@1437f03ce14a> # Security update for helm Announcement ID: SUSE-SU-2026:3050-1 Release Date: 2026-07-15T13:09:46Z Rating: important References: Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that can now be installed. ## Description: This update for helm rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3050=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3050=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3050=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3050=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3050=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3050=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3050=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3050=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3050=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3050=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3050=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3050=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3050=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.21.2-150000.1.82.1 * helm-bash-completion-3.21.2-150000.1.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-debuginfo-3.21.2-150000.1.82.1 * helm-3.21.2-150000.1.82.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:50 -0000 Subject: SUSE-SU-2026:3049-1: important: Security update for distribution Message-ID: <178414763097.406.1868649028000474721@1437f03ce14a> # Security update for distribution Announcement ID: SUSE-SU-2026:3049-1 Release Date: 2026-07-15T13:08:15Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for distribution rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3049=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3049=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3049=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3049=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3049=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3049=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3049=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3049=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3049=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3049=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3049=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3049=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.36.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * distribution-registry-2.8.3-150400.9.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * distribution-registry-2.8.3-150400.9.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:33:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:33:55 -0000 Subject: SUSE-SU-2026:3048-1: important: Security update for container-suseconnect Message-ID: <178414763563.406.13272706211642646051@1437f03ce14a> # Security update for container-suseconnect Announcement ID: SUSE-SU-2026:3048-1 Release Date: 2026-07-15T13:07:18Z Rating: important References: Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for container-suseconnect rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3048=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3048=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3048=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3048=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3048=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3048=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3048=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3048=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3048=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3048=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3048=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * container-suseconnect-2.5.6-150000.4.90.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:34:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:34:11 -0000 Subject: SUSE-SU-2026:3047-1: important: Security update for go1.26-openssl Message-ID: <178414765168.406.279612700869023917@1437f03ce14a> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:3047-1 Release Date: 2026-07-15T13:06:11Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3047=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3047=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3047=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3047=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3047=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3047=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3047=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3047=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.26-openssl-doc-1.26.5-150000.1.12.1 * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.26-openssl-race-1.26.5-150000.1.12.1 * go1.26-openssl-1.26.5-150000.1.12.1 * go1.26-openssl-doc-1.26.5-150000.1.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:34:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:34:30 -0000 Subject: SUSE-SU-2026:3046-1: important: Security update for go1.25-openssl Message-ID: <178414767091.406.18339232767473331990@1437f03ce14a> # Security update for go1.25-openssl Announcement ID: SUSE-SU-2026:3046-1 Release Date: 2026-07-15T13:05:24Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves eight vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.25-openssl fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3046=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3046=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3046=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3046=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3046=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3046=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3046=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3046=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.12-150000.1.27.1 * go1.25-openssl-doc-1.25.12-150000.1.27.1 * go1.25-openssl-debuginfo-1.25.12-150000.1.27.1 * go1.25-openssl-race-1.25.12-150000.1.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Jul 15 20:34:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 15 Jul 2026 20:34:35 -0000 Subject: SUSE-SU-2026:3045-1: important: Security update for rootlesskit Message-ID: <178414767554.406.11860135597082199453@1437f03ce14a> # Security update for rootlesskit Announcement ID: SUSE-SU-2026:3045-1 Release Date: 2026-07-15T13:04:39Z Rating: important References: Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that can now be installed. ## Description: This update for rootlesskit rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3045=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3045=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3045=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3045=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3045=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3045=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3045=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3045=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rootlesskit-1.1.1-150000.1.13.1 * rootlesskit-debuginfo-1.1.1-150000.1.13.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 08:30:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 08:30:23 -0000 Subject: SUSE-SU-2026:3065-1: important: Security update for the Linux Kernel (Live Patch 74 for SUSE Linux Enterprise 12 SP5) Message-ID: <178419062322.503.17817711010680966625@178315a69387> # Security update for the Linux Kernel (Live Patch 74 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3065-1 Release Date: 2026-07-15T19:04:03Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.280 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3065=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_280-default-10-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:30:16 -0000 Subject: SUSE-SU-2026:3067-1: important: Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Message-ID: <178420501683.569.10572584182657812012@ddd703581f31> # Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3067-1 Release Date: 2026-07-16T02:04:19Z Rating: important References: * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-43037 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.310 fixes various security issues The following security issues were fixed: * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3067=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_310-default-3-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:30:34 -0000 Subject: SUSE-SU-2026:3066-1: important: Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) Message-ID: <178420503444.569.12208584344626625183@ddd703581f31> # Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:3066-1 Release Date: 2026-07-15T22:33:29Z Rating: important References: * bsc#1263670 * bsc#1264253 * bsc#1264849 * bsc#1265127 * bsc#1265197 * bsc#1266265 * bsc#1267206 Cross-References: * CVE-2026-31685 * CVE-2026-43025 * CVE-2026-43037 * CVE-2026-43190 * CVE-2026-43437 * CVE-2026-45970 * CVE-2026-46243 CVSS scores: * CVE-2026-31685 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31685 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31685 ( NVD ): 9.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43025 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43025 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-43037 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43037 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43037 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43190 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43190 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43190 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-43437 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43437 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43437 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.296 fixes various security issues The following security issues were fixed: * CVE-2026-31685: netfilter: ip6t_eui64: reject invalid MAC header for all packets (bsc#1263670). * CVE-2026-43025: netfilter: ctnetlink: ignore explicit helper on new expectations (bsc#1264253). * CVE-2026-43037: ip6_tunnel: clear skb2->cb[] in ip4ip6_err() (bsc#1265197). * CVE-2026-43190: netfilter: xt_tcpmss: check remaining length before reading optlen (bsc#1264849). * CVE-2026-43437: ALSA: pcm: fix use-after-free on linked stream runtime in snd_pcm_drain() (bsc#1265127). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-3066=1 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_296-default-6-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31685.html * https://www.suse.com/security/cve/CVE-2026-43025.html * https://www.suse.com/security/cve/CVE-2026-43037.html * https://www.suse.com/security/cve/CVE-2026-43190.html * https://www.suse.com/security/cve/CVE-2026-43437.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://bugzilla.suse.com/show_bug.cgi?id=1263670 * https://bugzilla.suse.com/show_bug.cgi?id=1264253 * https://bugzilla.suse.com/show_bug.cgi?id=1264849 * https://bugzilla.suse.com/show_bug.cgi?id=1265127 * https://bugzilla.suse.com/show_bug.cgi?id=1265197 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:30:44 -0000 Subject: SUSE-SU-2026:3071-1: important: Security update for podman Message-ID: <178420504467.569.2839686967755186268@ddd703581f31> # Security update for podman Announcement ID: SUSE-SU-2026:3071-1 Release Date: 2026-07-16T07:23:26Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for podman rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3071=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3071=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3071=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3071=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3071=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3071=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3071=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3071=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3071=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * openSUSE Leap 15.5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * Containers Module 15-SP7 (noarch) * podman-docker-4.9.5-150500.3.75.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * podman-docker-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * podman-remote-4.9.5-150500.3.75.1 * podmansh-4.9.5-150500.3.75.1 * podman-debuginfo-4.9.5-150500.3.75.1 * podman-remote-debuginfo-4.9.5-150500.3.75.1 * podman-4.9.5-150500.3.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.75.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:30:48 -0000 Subject: SUSE-SU-2026:3070-1: important: Security update for podman Message-ID: <178420504894.569.3832155168249068021@ddd703581f31> # Security update for podman Announcement ID: SUSE-SU-2026:3070-1 Release Date: 2026-07-16T02:34:18Z Rating: important References: Affected Products: * openSUSE Leap 15.3 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Server 15 SP3 An update that can now be installed. ## Description: This update for podman rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-3070=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3070=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * podman-4.9.5-150300.9.80.1 * podmansh-4.9.5-150300.9.80.1 * podman-debuginfo-4.9.5-150300.9.80.1 * podman-remote-4.9.5-150300.9.80.1 * podman-remote-debuginfo-4.9.5-150300.9.80.1 * openSUSE Leap 15.3 (noarch) * podman-docker-4.9.5-150300.9.80.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * podman-debuginfo-4.9.5-150300.9.80.1 * podman-4.9.5-150300.9.80.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:30:53 -0000 Subject: SUSE-SU-2026:3069-1: important: Security update for rekor Message-ID: <178420505323.569.3868163585315902407@ddd703581f31> # Security update for rekor Announcement ID: SUSE-SU-2026:3069-1 Release Date: 2026-07-16T02:34:04Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for rekor rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3069=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3069=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3069=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3069=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3069=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3069=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3069=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3069=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3069=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3069=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3069=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3069=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * rekor-debuginfo-1.4.3-150400.4.36.1 * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * rekor-1.4.3-150400.4.36.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:30:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:30:57 -0000 Subject: SUSE-SU-2026:3068-1: important: Security update for cosign Message-ID: <178420505737.569.397395095049078056@ddd703581f31> # Security update for cosign Announcement ID: SUSE-SU-2026:3068-1 Release Date: 2026-07-16T02:32:56Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for cosign rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3068=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3068=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3068=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3068=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3068=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3068=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3068=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3068=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3068=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 * openSUSE Leap 15.4 (noarch) * cosign-zsh-completion-3.1.1-150400.3.47.1 * cosign-bash-completion-3.1.1-150400.3.47.1 * cosign-fish-completion-3.1.1-150400.3.47.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * Basesystem Module 15-SP7 (noarch) * cosign-zsh-completion-3.1.1-150400.3.47.1 * cosign-bash-completion-3.1.1-150400.3.47.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cosign-3.1.1-150400.3.47.1 * cosign-debuginfo-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.1.1-150400.3.47.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 12:31:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 12:31:04 -0000 Subject: SUSE-SU-2026:2854-2: moderate: Security update for python-urllib3 Message-ID: <178420506470.569.3293930017243201711@ddd703581f31> # Security update for python-urllib3 Announcement ID: SUSE-SU-2026:2854-2 Release Date: 2026-07-16T02:26:06Z Rating: moderate References: * bsc#1254867 * bsc#1270365 Cross-References: * CVE-2025-66471 CVSS scores: * CVE-2025-66471 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-66471 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-66471 ( NVD ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-66471 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for python-urllib3 fixes the following issue * Regression introduced by CVE-2025-66471 fix during file download with pySSL (bsc#1270365). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-2854=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-2854=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-2854=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-2854=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-2854=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-2854=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-2854=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python3-urllib3-1.25.10-150300.4.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-66471.html * https://bugzilla.suse.com/show_bug.cgi?id=1254867 * https://bugzilla.suse.com/show_bug.cgi?id=1270365 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:30:26 -0000 Subject: SUSE-SU-2026:22660-1: important: Security update for python-soupsieve Message-ID: <178421942613.660.17127190369028946581@1437f03ce14a> # Security update for python-soupsieve Announcement ID: SUSE-SU-2026:22660-1 Release Date: 2026-07-14T10:43:25Z Rating: important References: * bsc#1271187 * bsc#1271188 Cross-References: * CVE-2026-49476 * CVE-2026-49477 CVSS scores: * CVE-2026-49476 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49476 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-49477 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-soupsieve fixes the following issues * CVE-2026-49476: Memory Exhaustion via Large Comma-Separated Selector Lists (bsc#1271187). * CVE-2026-49477: Regular Expression Denial of Service (ReDoS) via Selector Parser (bsc#1271188). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1246=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1246=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-soupsieve-2.6-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-soupsieve-2.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49476.html * https://www.suse.com/security/cve/CVE-2026-49477.html * https://bugzilla.suse.com/show_bug.cgi?id=1271187 * https://bugzilla.suse.com/show_bug.cgi?id=1271188 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:30:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:30:48 -0000 Subject: SUSE-SU-2026:22657-1: moderate: Security update for python-sqlparse Message-ID: <178421944892.660.16355276187387074609@1437f03ce14a> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:22657-1 Release Date: 2026-07-14T10:41:18Z Rating: moderate References: * bsc#1268597 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for python-sqlparse fixes the following issues: Changes in python-sqlparse: * GHSA-27jp-wm6q-gp25: Limit recursion during parsing of tuples. (bsc#1268597) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1247=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1247=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-sqlparse-0.5.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-sqlparse-0.5.3-160000.3.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1268597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:31:01 -0000 Subject: SUSE-SU-2026:22656-1: important: Security update for go1.26 Message-ID: <178421946141.660.7282717215925705756@1437f03ce14a> # Security update for go1.26 Announcement ID: SUSE-SU-2026:22656-1 Release Date: 2026-07-14T10:41:18Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for go1.26 fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1245=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1245=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-race-1.26.5-160000.1.1 * go1.26-doc-1.26.5-160000.1.1 * go1.26-1.26.5-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-doc-1.26.5-160000.1.1 * go1.26-race-1.26.5-160000.1.1 * go1.26-1.26.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:31:18 -0000 Subject: SUSE-SU-2026:22655-1: moderate: Security update for python-mistune Message-ID: <178421947808.660.13892495803602922630@1437f03ce14a> # Security update for python-mistune Announcement ID: SUSE-SU-2026:22655-1 Release Date: 2026-07-14T10:41:18Z Rating: moderate References: * bsc#1271082 * bsc#1271117 * bsc#1271119 * bsc#1271121 * bsc#1271125 * bsc#1271127 * bsc#1271128 * bsc#1271131 * bsc#1271132 Cross-References: * CVE-2026-44896 * CVE-2026-59922 * CVE-2026-59923 * CVE-2026-59924 * CVE-2026-59925 * CVE-2026-59926 * CVE-2026-59927 * CVE-2026-59928 * CVE-2026-59929 * CVE-2026-59930 CVSS scores: * CVE-2026-44896 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-44896 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-44896 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44896 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59922 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59922 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59922 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59923 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59923 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59923 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59924 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59924 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59924 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59925 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59925 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59925 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59926 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59926 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59926 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59926 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59927 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59927 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59928 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59928 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59929 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-59929 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-59930 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-59930 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for python-mistune fixes the following issues * CVE-2026-59922: quadratic-time parsing on long runs of some markers in `formatting.py` can lead to DoS (bsc#1271117). * CVE-2026-59923: `HTMLRenderer.safe_url()` does not block percent-encoded javascript URIs and allows for XSS (bsc#1271119). * CVE-2026-59924: improper processing of user-supplied include paths in `Include.parse()` can lead to path traversal and arbitrary file reads (bsc#1271121). * CVE-2026-59925: quadratic-time parsing on long runs of some emphasis pairs in `inline_parser` can lead to DoS (bsc#1271125). * CVE-2026-59926: improper escaping in `render_admonition()` can lead to atribute injection and XSS (bsc#1271127). * CVE-2026-59927: uncontrolled recursion when processing two markdown files that include each other can lead to a DoS (bsc#1271128). * CVE-2026-59928: quadratic-time parsing on long lists of repeated reference- link definitions in `block_parser` can lead to DoS (bsc#1271131). * CVE-2026-59929: HARMFUL_PROTOCOLS list misses legacy and chained schemes and allow arbitrary script execution in user agents (bsc#1271132). * CVE-2026-59930: the `toc` plugin and `TableOfContents` directive generate heading IDs with predictable values and allow for collisions with attacker- controlled `id="toc_N"` content (bsc#1271082). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1243=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1243=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-mistune-3.1.3-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-mistune-3.1.3-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44896.html * https://www.suse.com/security/cve/CVE-2026-59922.html * https://www.suse.com/security/cve/CVE-2026-59923.html * https://www.suse.com/security/cve/CVE-2026-59924.html * https://www.suse.com/security/cve/CVE-2026-59925.html * https://www.suse.com/security/cve/CVE-2026-59926.html * https://www.suse.com/security/cve/CVE-2026-59927.html * https://www.suse.com/security/cve/CVE-2026-59928.html * https://www.suse.com/security/cve/CVE-2026-59929.html * https://www.suse.com/security/cve/CVE-2026-59930.html * https://bugzilla.suse.com/show_bug.cgi?id=1271082 * https://bugzilla.suse.com/show_bug.cgi?id=1271117 * https://bugzilla.suse.com/show_bug.cgi?id=1271119 * https://bugzilla.suse.com/show_bug.cgi?id=1271121 * https://bugzilla.suse.com/show_bug.cgi?id=1271125 * https://bugzilla.suse.com/show_bug.cgi?id=1271127 * https://bugzilla.suse.com/show_bug.cgi?id=1271128 * https://bugzilla.suse.com/show_bug.cgi?id=1271131 * https://bugzilla.suse.com/show_bug.cgi?id=1271132 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:31:34 -0000 Subject: SUSE-SU-2026:22653-1: moderate: Security update for openexr Message-ID: <178421949420.660.3616764725953118548@1437f03ce14a> # Security update for openexr Announcement ID: SUSE-SU-2026:22653-1 Release Date: 2026-07-14T08:46:15Z Rating: moderate References: * bsc#1269701 * bsc#1269702 * bsc#1269703 Cross-References: * CVE-2026-54920 * CVE-2026-55059 * CVE-2026-55373 CVSS scores: * CVE-2026-54920 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55059 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-55373 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for openexr fixes the following issues * CVE-2026-54920: unchecked integer overflows in Image::resize() followed by an exception can lead to an invalid delete via uninitialized pointers (bsc#1269703). * CVE-2026-55059: row setter utilizing dataWindow.min.x instead of min.y can lead to a heap out-of-bounds write (bsc#1269702). * CVE-2026-55373: integer overflow in roundListSizeUp() wrapping a 32-bit unsigned value to zero can lead to an infinite loop (bsc#1269701). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1240=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1240=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * openexr-doc-3.2.2-160000.9.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libOpenEXR-3_2-31-3.2.2-160000.9.1 * libIex-3_2-31-debuginfo-3.2.2-160000.9.1 * libIex-3_2-31-3.2.2-160000.9.1 * openexr-3.2.2-160000.9.1 * libIlmThread-3_2-31-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-3.2.2-160000.9.1 * libOpenEXR-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debuginfo-3.2.2-160000.9.1 * libIlmThread-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debugsource-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-3.2.2-160000.9.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIlmThread-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libOpenEXR-3_2-31-3.2.2-160000.9.1 * libIex-3_2-31-debuginfo-3.2.2-160000.9.1 * libIex-3_2-31-3.2.2-160000.9.1 * openexr-3.2.2-160000.9.1 * libIlmThread-3_2-31-3.2.2-160000.9.1 * libOpenEXR-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-debuginfo-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debuginfo-3.2.2-160000.9.1 * libIlmThread-3_2-31-debuginfo-3.2.2-160000.9.1 * openexr-debugsource-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-3.2.2-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libIlmThread-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.9.1 * libIex-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openexr-doc-3.2.2-160000.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54920.html * https://www.suse.com/security/cve/CVE-2026-55059.html * https://www.suse.com/security/cve/CVE-2026-55373.html * https://bugzilla.suse.com/show_bug.cgi?id=1269701 * https://bugzilla.suse.com/show_bug.cgi?id=1269702 * https://bugzilla.suse.com/show_bug.cgi?id=1269703 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:31:45 -0000 Subject: SUSE-SU-2026:22651-1: low: Security update for patch Message-ID: <178421950512.660.4656738938420010341@1437f03ce14a> # Security update for patch Announcement ID: SUSE-SU-2026:22651-1 Release Date: 2026-07-13T19:29:50Z Rating: low References: * bsc#1271166 * bsc#1271167 Cross-References: * CVE-2026-56288 * CVE-2026-56289 CVSS scores: * CVE-2026-56288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56288 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56288 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2026-56289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56289 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56289 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for patch fixes the following issues * CVE-2026-56288: crafted unified-diff patch file can cause null pointer derefence (bsc#1271167). * CVE-2026-56289: improper validation of hunk line offsets can lead to denial of service (bsc#1271166). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1236=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1236=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * patch-debuginfo-2.7.6-160000.4.1 * patch-2.7.6-160000.4.1 * patch-debugsource-2.7.6-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * patch-debuginfo-2.7.6-160000.4.1 * patch-2.7.6-160000.4.1 * patch-debugsource-2.7.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56288.html * https://www.suse.com/security/cve/CVE-2026-56289.html * https://bugzilla.suse.com/show_bug.cgi?id=1271166 * https://bugzilla.suse.com/show_bug.cgi?id=1271167 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:31:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:31:50 -0000 Subject: SUSE-SU-2026:22650-1: low: Security update for helm Message-ID: <178421951050.660.5050833979566421136@1437f03ce14a> # Security update for helm Announcement ID: SUSE-SU-2026:22650-1 Release Date: 2026-07-13T19:24:02Z Rating: low References: * bsc#1270127 Cross-References: * CVE-2026-48978 CVSS scores: * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for helm fixes the following issue * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). Changes for helm: * Update to version 3.21.2. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1235=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1235=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 s390x x86_64) * helm-debuginfo-3.21.2-160000.2.1 * helm-3.21.2-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * helm-zsh-completion-3.21.2-160000.2.1 * helm-fish-completion-3.21.2-160000.2.1 * helm-bash-completion-3.21.2-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-zsh-completion-3.21.2-160000.2.1 * helm-fish-completion-3.21.2-160000.2.1 * helm-bash-completion-3.21.2-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * helm-debuginfo-3.21.2-160000.2.1 * helm-3.21.2-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48978.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:32:10 -0000 Subject: SUSE-SU-2026:22648-1: moderate: Security update for tomcat11 Message-ID: <178421953074.660.16525607929494005762@1437f03ce14a> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:22648-1 Release Date: 2026-07-13T16:24:32Z Rating: moderate References: * bsc#1232390 * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities and has one fix can now be installed. ## Description: This update for tomcat11 fixes the following issues Update to Tomcat 11.0.23. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Upgrade libtcnative to v2 (bsc#1232390) * Tomcat 11.0.23: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Lower the log level to debug when OpenSSL initialization fails in OpenSSLLifecycleListener to avoid stack traces when libssl.so is not present and to align the behavior of the isAvailable() check with the AprLifecycleListener and gracefully fail when natives are not present. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix SSO cookie partitioned configuration. (remm) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Update default web.xml version to match supported Servlet specification version. (markt) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This us a breaking change for the EncryptInterceptor.(markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1233=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1233=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat11-doc-11.0.23-160000.1.1 * tomcat11-11.0.23-160000.1.1 * tomcat11-embed-11.0.23-160000.1.1 * tomcat11-jsvc-11.0.23-160000.1.1 * tomcat11-docs-webapp-11.0.23-160000.1.1 * tomcat11-webapps-11.0.23-160000.1.1 * tomcat11-jsp-4_0-api-11.0.23-160000.1.1 * tomcat11-lib-11.0.23-160000.1.1 * tomcat11-el-6_0-api-11.0.23-160000.1.1 * tomcat11-admin-webapps-11.0.23-160000.1.1 * tomcat11-servlet-6_1-api-11.0.23-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat11-doc-11.0.23-160000.1.1 * tomcat11-embed-11.0.23-160000.1.1 * tomcat11-jsvc-11.0.23-160000.1.1 * tomcat11-webapps-11.0.23-160000.1.1 * tomcat11-docs-webapp-11.0.23-160000.1.1 * tomcat11-jsp-4_0-api-11.0.23-160000.1.1 * tomcat11-el-6_0-api-11.0.23-160000.1.1 * tomcat11-lib-11.0.23-160000.1.1 * tomcat11-11.0.23-160000.1.1 * tomcat11-admin-webapps-11.0.23-160000.1.1 * tomcat11-servlet-6_1-api-11.0.23-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1232390 * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:32:23 -0000 Subject: SUSE-SU-2026:22647-1: moderate: Security update for tomcat10 Message-ID: <178421954332.660.14932609740489982099@1437f03ce14a> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:22647-1 Release Date: 2026-07-13T16:24:32Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues Update to Tomcat 10.1.56. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 10.1.56: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1232=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1232=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat10-admin-webapps-10.1.56-160000.1.1 * tomcat10-lib-10.1.56-160000.1.1 * tomcat10-servlet-6_0-api-10.1.56-160000.1.1 * tomcat10-jsp-3_1-api-10.1.56-160000.1.1 * tomcat10-docs-webapp-10.1.56-160000.1.1 * tomcat10-webapps-10.1.56-160000.1.1 * tomcat10-jsvc-10.1.56-160000.1.1 * tomcat10-10.1.56-160000.1.1 * tomcat10-doc-10.1.56-160000.1.1 * tomcat10-el-5_0-api-10.1.56-160000.1.1 * tomcat10-embed-10.1.56-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat10-admin-webapps-10.1.56-160000.1.1 * tomcat10-lib-10.1.56-160000.1.1 * tomcat10-servlet-6_0-api-10.1.56-160000.1.1 * tomcat10-jsp-3_1-api-10.1.56-160000.1.1 * tomcat10-webapps-10.1.56-160000.1.1 * tomcat10-jsvc-10.1.56-160000.1.1 * tomcat10-docs-webapp-10.1.56-160000.1.1 * tomcat10-10.1.56-160000.1.1 * tomcat10-doc-10.1.56-160000.1.1 * tomcat10-el-5_0-api-10.1.56-160000.1.1 * tomcat10-embed-10.1.56-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:32:36 -0000 Subject: SUSE-SU-2026:22646-1: moderate: Security update for tomcat Message-ID: <178421955624.660.17274759095456958289@1437f03ce14a> # Security update for tomcat Announcement ID: SUSE-SU-2026:22646-1 Release Date: 2026-07-13T16:24:32Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues Update to Tomcat 9.0.119. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 9.0.119: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Wrong references to jakarta instead of javax. (remm) * Fix: Restore default authenticator to nullafter executing an Ant task. (remm) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update Tomcat Native to 1.3.8. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1231=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1231=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat-lib-9.0.119-160000.1.1 * tomcat-webapps-9.0.119-160000.1.1 * tomcat-el-3_0-api-9.0.119-160000.1.1 * tomcat-9.0.119-160000.1.1 * tomcat-jsp-2_3-api-9.0.119-160000.1.1 * tomcat-embed-9.0.119-160000.1.1 * tomcat-jsvc-9.0.119-160000.1.1 * tomcat-admin-webapps-9.0.119-160000.1.1 * tomcat-servlet-4_0-api-9.0.119-160000.1.1 * tomcat-docs-webapp-9.0.119-160000.1.1 * tomcat-javadoc-9.0.119-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat-lib-9.0.119-160000.1.1 * tomcat-webapps-9.0.119-160000.1.1 * tomcat-el-3_0-api-9.0.119-160000.1.1 * tomcat-9.0.119-160000.1.1 * tomcat-jsp-2_3-api-9.0.119-160000.1.1 * tomcat-embed-9.0.119-160000.1.1 * tomcat-jsvc-9.0.119-160000.1.1 * tomcat-admin-webapps-9.0.119-160000.1.1 * tomcat-servlet-4_0-api-9.0.119-160000.1.1 * tomcat-docs-webapp-9.0.119-160000.1.1 * tomcat-javadoc-9.0.119-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:32:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:32:43 -0000 Subject: SUSE-SU-2026:22645-1: moderate: Security update for cryptsetup Message-ID: <178421956308.660.17810415356059496808@1437f03ce14a> # Security update for cryptsetup Announcement ID: SUSE-SU-2026:22645-1 Release Date: 2026-07-13T16:23:16Z Rating: moderate References: * bsc#1270252 * bsc#1270254 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has two fixes can now be installed. ## Description: This update for cryptsetup fixes the following issues: Changes in cryptsetup: * Fix for (bsc#1270254) to avoid undesired pinning of all volume keys (via the thread keyring) through the caller's credentials when the kernel opens a file. This is due to the refactoring in kernel commit a28d893eb327 ("md: port block device access to file") that accidentally causes the caller's thread keyring to be kept alive long beyond the caller's lifetime, the kernel part is tracked in (bsc#1270252). * Add keyring key type. [b6fb6fc0] * Load volume keys in intermediary keyring linked in thread keyring. [413a3dd0] * Use unique intermediary keyring name per device. [04ef07a7] * Add regression tests. [bfcb0c38, bb5e8e9f, e6573494, aa214c09] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1229=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1229=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cryptsetup-debugsource-2.8.4-160000.2.1 * cryptsetup-2.8.4-160000.2.1 * libcryptsetup12-2.8.4-160000.2.1 * cryptsetup-ssh-debuginfo-2.8.4-160000.2.1 * cryptsetup-ssh-2.8.4-160000.2.1 * libcryptsetup-devel-2.8.4-160000.2.1 * cryptsetup-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-debuginfo-2.8.4-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * cryptsetup-doc-2.8.4-160000.2.1 * cryptsetup-lang-2.8.4-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * cryptsetup-doc-2.8.4-160000.2.1 * cryptsetup-lang-2.8.4-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cryptsetup-debugsource-2.8.4-160000.2.1 * cryptsetup-2.8.4-160000.2.1 * cryptsetup-ssh-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-2.8.4-160000.2.1 * cryptsetup-ssh-2.8.4-160000.2.1 * libcryptsetup-devel-2.8.4-160000.2.1 * cryptsetup-debuginfo-2.8.4-160000.2.1 * libcryptsetup12-debuginfo-2.8.4-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1270252 * https://bugzilla.suse.com/show_bug.cgi?id=1270254 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:33:03 -0000 Subject: SUSE-SU-2026:22643-1: important: Security update for go1.25 Message-ID: <178421958314.660.516558448229167784@1437f03ce14a> # Security update for go1.25 Announcement ID: SUSE-SU-2026:22643-1 Release Date: 2026-07-13T14:32:00Z Rating: important References: * bsc#1244485 * bsc#1245878 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1264394 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 Cross-References: * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27142 * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities, contains one feature and has three fixes can now be installed. ## Description: This update for go1.25 fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1228=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1228=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.25-1.25.12-160000.1.1 * go1.25-doc-1.25.12-160000.1.1 * go1.25-race-1.25.12-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.25-1.25.12-160000.1.1 * go1.25-doc-1.25.12-160000.1.1 * go1.25-race-1.25.12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:33:25 -0000 Subject: SUSE-SU-2026:22641-1: important: Security update for go1.26-openssl Message-ID: <178421960556.660.11684033952806815344@1437f03ce14a> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:22641-1 Release Date: 2026-07-13T13:59:29Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-39822 * CVE-2026-42505 CVSS scores: * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities, contains two features and has three fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1225=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1225=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-openssl-1.26.5-160000.1.1 * go1.26-openssl-race-1.26.5-160000.1.1 * go1.26-openssl-doc-1.26.5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-1.26.5-160000.1.1 * go1.26-openssl-race-1.26.5-160000.1.1 * go1.26-openssl-doc-1.26.5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:33:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:33:41 -0000 Subject: SUSE-SU-2026:22639-1: moderate: Security update for pam Message-ID: <178421962116.660.9529519609474233645@1437f03ce14a> # Security update for pam Announcement ID: SUSE-SU-2026:22639-1 Release Date: 2026-07-13T13:54:56Z Rating: moderate References: * bsc#1268290 Cross-References: * CVE-2026-54411 CVSS scores: * CVE-2026-54411 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-54411 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:X/U:X * CVE-2026-54411 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for pam fixes the following issue * CVE-2026-54411: timing discrepancy in the `pam_userdb` module's plaintext- password comparison (bsc#1268290). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1224=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1224=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * pam-manpages-1.7.1-160000.5.1 * pam-doc-1.7.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * pam-devel-1.7.1-160000.5.1 * pam-extra-debuginfo-1.7.1-160000.5.1 * pam-extra-1.7.1-160000.5.1 * pam-debuginfo-1.7.1-160000.5.1 * pam-1.7.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x) * pam-full-src-debugsource-1.7.1-160000.5.1 * pam-debugsource-1.7.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * pam-devel-1.7.1-160000.5.1 * pam-extra-debuginfo-1.7.1-160000.5.1 * pam-extra-1.7.1-160000.5.1 * pam-debuginfo-1.7.1-160000.5.1 * pam-1.7.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le) * pam-full-src-debugsource-1.7.1-160000.5.1 * pam-debugsource-1.7.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * pam-manpages-1.7.1-160000.5.1 * pam-doc-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54411.html * https://bugzilla.suse.com/show_bug.cgi?id=1268290 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:34:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:34:37 -0000 Subject: SUSE-SU-2026:22638-1: critical: Security update for go1.25-openssl Message-ID: <178421967730.660.8352457002069460363@1437f03ce14a> # Security update for go1.25-openssl Announcement ID: SUSE-SU-2026:22638-1 Release Date: 2026-07-13T12:52:40Z Rating: critical References: * bsc#1170826 * bsc#1244485 * bsc#1245878 * bsc#1256818 * bsc#1257692 * bsc#1259264 * bsc#1259265 * bsc#1259268 * bsc#1261653 * bsc#1261654 * bsc#1261655 * bsc#1261656 * bsc#1261657 * bsc#1261658 * bsc#1261659 * bsc#1261660 * bsc#1261661 * bsc#1264394 * bsc#1264499 * bsc#1264500 * bsc#1264501 * bsc#1264502 * bsc#1264503 * bsc#1264504 * bsc#1264505 * bsc#1264506 * bsc#1264507 * bsc#1264508 * bsc#1264509 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2025-61732 * CVE-2025-68121 * CVE-2026-25679 * CVE-2026-27139 * CVE-2026-27140 * CVE-2026-27142 * CVE-2026-27143 * CVE-2026-27144 * CVE-2026-27145 * CVE-2026-32280 * CVE-2026-32281 * CVE-2026-32282 * CVE-2026-32283 * CVE-2026-32288 * CVE-2026-32289 * CVE-2026-33811 * CVE-2026-33814 * CVE-2026-39817 * CVE-2026-39819 * CVE-2026-39820 * CVE-2026-39822 * CVE-2026-39823 * CVE-2026-39825 * CVE-2026-39826 * CVE-2026-39836 * CVE-2026-42499 * CVE-2026-42501 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2025-61732 ( SUSE ): 9.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2025-61732 ( SUSE ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2025-61732 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-68121 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2025-68121 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-68121 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-25679 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-25679 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25679 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27139 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-27139 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27139 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-27140 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-27140 ( NVD ): 9.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H * CVE-2026-27142 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-27142 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-27142 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27143 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-27144 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27144 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32280 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32281 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32282 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32282 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-32283 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32283 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-32288 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32288 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-32289 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-32289 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33811 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33811 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39817 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39817 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N * CVE-2026-39819 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39819 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-39820 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39820 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39823 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39823 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39825 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39825 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-39826 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39826 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-39836 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39836 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42499 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42501 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 30 vulnerabilities, contains two features and has four fixes can now be installed. ## Description: This update for go1.25-openssl fixes the following issues * Update to version go1.25.12 (bsc#1244485). * CVE-2025-61732: cmd/cgo: discrepancy between Go and C/C++ comment parsing allows for C code smuggling (bsc#1257692). * CVE-2025-68121: crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain (bsc#1256818). * CVE-2026-25679: net/url: reject IPv6 literal not at start of host (bsc#1259264). * CVE-2026-27139: os: FileInfo can escape from a Root (bsc#1259268). * CVE-2026-27140: cmd/go: trust layer bypass when using cgo and SWIG (bsc#1261653). * CVE-2026-27142: html/template: URLs in meta content attribute actions are not escaped (bsc#1259265). * CVE-2026-27143: cmd/compile: possible memory corruption after bound check elimination (bsc#1261654). * CVE-2026-27144: cmd/compile: no-op interface conversion bypasses overlap checking (bsc#1261655). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-32280: crypto/x509: unexpected work during chain building (bsc#1261656). * CVE-2026-32281: crypto/x509: inefficient policy validation (bsc#1261657). * CVE-2026-32282: os: Root.Chmod can follow symlinks out of the root on Linux (bsc#1261658). * CVE-2026-32283: crypto/tls: multiple key update handshake messages can cause connection to deadlock (bsc#1261659). * CVE-2026-32288: archive/tar: unbounded allocation when parsing old format GNU sparse map (bsc#1261660). * CVE-2026-32289: html/template: JS template literal context incorrectly tracked (bsc#1261661). * CVE-2026-33811: net: crash when handling long CNAME response (bsc#1264508). * CVE-2026-33814: net/http: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1264506). * CVE-2026-39817: cmd/go: "go tool pack" does not sanitize output paths (bsc#1264505). * CVE-2026-39819: cmd/go: "go bug" follows symlinks in predictable temporary filenames (bsc#1264504). * CVE-2026-39820: net/mail: quadratic string concatentation in consumeComment (bsc#1264503). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-39823: html/template: bypass of meta content URL escaping causes XSS (bsc#1264509). * CVE-2026-39825: net/http/httputil: ReverseProxy forwards queries with more than urlmaxqueryparams parameters (bsc#1264500). * CVE-2026-39826: html/template: escaper bypass leads to XSS (bsc#1264507). * CVE-2026-39836: net: panic in Dial and LookupPort when handling NUL byte on Windows (bsc#1264501). * CVE-2026-42499: net/mail: quadratic string concatenation in consumePhrase (bsc#1264502). * CVE-2026-42501: cmd/go: malicious module proxy can bypass checksum database (bsc#1264499). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1223=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1223=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.25-openssl-doc-1.25.12-160000.1.1 * go1.25-openssl-race-1.25.12-160000.1.1 * go1.25-openssl-debuginfo-1.25.12-160000.1.1 * go1.25-openssl-1.25.12-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.25-openssl-doc-1.25.12-160000.1.1 * go1.25-openssl-race-1.25.12-160000.1.1 * go1.25-openssl-1.25.12-160000.1.1 * go1.25-openssl-debuginfo-1.25.12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61732.html * https://www.suse.com/security/cve/CVE-2025-68121.html * https://www.suse.com/security/cve/CVE-2026-25679.html * https://www.suse.com/security/cve/CVE-2026-27139.html * https://www.suse.com/security/cve/CVE-2026-27140.html * https://www.suse.com/security/cve/CVE-2026-27142.html * https://www.suse.com/security/cve/CVE-2026-27143.html * https://www.suse.com/security/cve/CVE-2026-27144.html * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-32280.html * https://www.suse.com/security/cve/CVE-2026-32281.html * https://www.suse.com/security/cve/CVE-2026-32282.html * https://www.suse.com/security/cve/CVE-2026-32283.html * https://www.suse.com/security/cve/CVE-2026-32288.html * https://www.suse.com/security/cve/CVE-2026-32289.html * https://www.suse.com/security/cve/CVE-2026-33811.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39817.html * https://www.suse.com/security/cve/CVE-2026-39819.html * https://www.suse.com/security/cve/CVE-2026-39820.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-39823.html * https://www.suse.com/security/cve/CVE-2026-39825.html * https://www.suse.com/security/cve/CVE-2026-39826.html * https://www.suse.com/security/cve/CVE-2026-39836.html * https://www.suse.com/security/cve/CVE-2026-42499.html * https://www.suse.com/security/cve/CVE-2026-42501.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1170826 * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1256818 * https://bugzilla.suse.com/show_bug.cgi?id=1257692 * https://bugzilla.suse.com/show_bug.cgi?id=1259264 * https://bugzilla.suse.com/show_bug.cgi?id=1259265 * https://bugzilla.suse.com/show_bug.cgi?id=1259268 * https://bugzilla.suse.com/show_bug.cgi?id=1261653 * https://bugzilla.suse.com/show_bug.cgi?id=1261654 * https://bugzilla.suse.com/show_bug.cgi?id=1261655 * https://bugzilla.suse.com/show_bug.cgi?id=1261656 * https://bugzilla.suse.com/show_bug.cgi?id=1261657 * https://bugzilla.suse.com/show_bug.cgi?id=1261658 * https://bugzilla.suse.com/show_bug.cgi?id=1261659 * https://bugzilla.suse.com/show_bug.cgi?id=1261660 * https://bugzilla.suse.com/show_bug.cgi?id=1261661 * https://bugzilla.suse.com/show_bug.cgi?id=1264394 * https://bugzilla.suse.com/show_bug.cgi?id=1264499 * https://bugzilla.suse.com/show_bug.cgi?id=1264500 * https://bugzilla.suse.com/show_bug.cgi?id=1264501 * https://bugzilla.suse.com/show_bug.cgi?id=1264502 * https://bugzilla.suse.com/show_bug.cgi?id=1264503 * https://bugzilla.suse.com/show_bug.cgi?id=1264504 * https://bugzilla.suse.com/show_bug.cgi?id=1264505 * https://bugzilla.suse.com/show_bug.cgi?id=1264506 * https://bugzilla.suse.com/show_bug.cgi?id=1264507 * https://bugzilla.suse.com/show_bug.cgi?id=1264508 * https://bugzilla.suse.com/show_bug.cgi?id=1264509 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:34:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:34:48 -0000 Subject: SUSE-SU-2026:22637-1: important: Security update for jq Message-ID: <178421968875.660.15916595500511301521@1437f03ce14a> # Security update for jq Announcement ID: SUSE-SU-2026:22637-1 Release Date: 2026-07-13T10:47:46Z Rating: important References: * bsc#1265075 * bsc#1265076 * bsc#1269220 * bsc#1269390 Cross-References: * CVE-2026-43896 * CVE-2026-44777 * CVE-2026-49839 * CVE-2026-54679 CVSS scores: * CVE-2026-43896 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44777 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44777 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-54679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues * CVE-2026-43896: unbounded recursion in jv_object_merge_recursive() can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-49839: fixed a bug where jq --rawfile can turn a handled oversized- string error into invalid-state reuse and a real heap out-of-bounds write in assertion-disabled builds (bsc#1269220). * CVE-2026-54679: integer overflow in jvp_string_append can lead to a buffer overrun on 32-bit systems (bsc#1269390). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1221=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1221=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jq-debugsource-1.7.1-160000.4.1 * libjq-devel-1.7.1-160000.4.1 * libjq1-1.7.1-160000.4.1 * jq-1.7.1-160000.4.1 * libjq1-debuginfo-1.7.1-160000.4.1 * jq-debuginfo-1.7.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jq-debugsource-1.7.1-160000.4.1 * libjq-devel-1.7.1-160000.4.1 * libjq1-1.7.1-160000.4.1 * jq-1.7.1-160000.4.1 * libjq1-debuginfo-1.7.1-160000.4.1 * jq-debuginfo-1.7.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43896.html * https://www.suse.com/security/cve/CVE-2026-44777.html * https://www.suse.com/security/cve/CVE-2026-49839.html * https://www.suse.com/security/cve/CVE-2026-54679.html * https://bugzilla.suse.com/show_bug.cgi?id=1265075 * https://bugzilla.suse.com/show_bug.cgi?id=1265076 * https://bugzilla.suse.com/show_bug.cgi?id=1269220 * https://bugzilla.suse.com/show_bug.cgi?id=1269390 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:34:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:34:56 -0000 Subject: SUSE-SU-2026:22636-1: important: Security update for libxml2 Message-ID: <178421969620.660.13299147759652403315@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:22636-1 Release Date: 2026-07-13T07:49:58Z Rating: important References: * bsc#1262719 * bsc#1269790 Cross-References: * CVE-2026-11979 * CVE-2026-6732 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6732 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6732 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6732 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libxml2 fixes the following issues * CVE-2026-6732: crafted XSD-validated document can cause a denial of service (bsc#1262719). * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1220=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1220=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-libxml2-2.13.8-160000.5.1 * libxml2-devel-2.13.8-160000.5.1 * python313-libxml2-debuginfo-2.13.8-160000.5.1 * libxml2-2-2.13.8-160000.5.1 * libxml2-debugsource-2.13.8-160000.5.1 * libxml2-tools-debuginfo-2.13.8-160000.5.1 * libxml2-python-debugsource-2.13.8-160000.5.1 * libxml2-tools-2.13.8-160000.5.1 * libxml2-2-debuginfo-2.13.8-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * libxml2-doc-2.13.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * libxml2-doc-2.13.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-libxml2-2.13.8-160000.5.1 * libxml2-devel-2.13.8-160000.5.1 * python313-libxml2-debuginfo-2.13.8-160000.5.1 * libxml2-tools-debuginfo-2.13.8-160000.5.1 * libxml2-debugsource-2.13.8-160000.5.1 * libxml2-python-debugsource-2.13.8-160000.5.1 * libxml2-2-debuginfo-2.13.8-160000.5.1 * libxml2-tools-2.13.8-160000.5.1 * libxml2-2-2.13.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://www.suse.com/security/cve/CVE-2026-6732.html * https://bugzilla.suse.com/show_bug.cgi?id=1262719 * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:35:04 -0000 Subject: SUSE-SU-2026:22635-1: moderate: Security update for php8 Message-ID: <178421970431.660.5885755962231463368@1437f03ce14a> # Security update for php8 Announcement ID: SUSE-SU-2026:22635-1 Release Date: 2026-07-12T13:00:50Z Rating: moderate References: * bsc#1270351 * bsc#1270712 Cross-References: * CVE-2026-12184 * CVE-2026-14355 CVSS scores: * CVE-2026-12184 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14355 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-14355 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14355 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14355 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for php8 fixes the following issues * Update to versio 8.4.23 * CVE-2026-14355: The AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw (bsc#1270351). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1219=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1219=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * php8-fpm-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-8.4.23-160000.1.1 * php8-iconv-8.4.23-160000.1.1 * php8-sysvmsg-8.4.23-160000.1.1 * php8-fileinfo-8.4.23-160000.1.1 * php8-pdo-8.4.23-160000.1.1 * php8-xmlreader-debuginfo-8.4.23-160000.1.1 * php8-gd-debuginfo-8.4.23-160000.1.1 * php8-gd-8.4.23-160000.1.1 * php8-tokenizer-8.4.23-160000.1.1 * php8-soap-8.4.23-160000.1.1 * php8-openssl-8.4.23-160000.1.1 * php8-sysvmsg-debuginfo-8.4.23-160000.1.1 * php8-zip-8.4.23-160000.1.1 * php8-xmlreader-8.4.23-160000.1.1 * php8-gmp-debuginfo-8.4.23-160000.1.1 * php8-sockets-debuginfo-8.4.23-160000.1.1 * php8-bz2-8.4.23-160000.1.1 * php8-embed-debuginfo-8.4.23-160000.1.1 * php8-mbstring-debuginfo-8.4.23-160000.1.1 * php8-zlib-debuginfo-8.4.23-160000.1.1 * php8-opcache-8.4.23-160000.1.1 * php8-calendar-debuginfo-8.4.23-160000.1.1 * php8-debugsource-8.4.23-160000.1.1 * php8-zlib-8.4.23-160000.1.1 * php8-sysvshm-8.4.23-160000.1.1 * php8-embed-8.4.23-160000.1.1 * php8-posix-debuginfo-8.4.23-160000.1.1 * php8-zip-debuginfo-8.4.23-160000.1.1 * php8-embed-debugsource-8.4.23-160000.1.1 * php8-pcntl-debuginfo-8.4.23-160000.1.1 * apache2-mod_php8-debugsource-8.4.23-160000.1.1 * php8-bz2-debuginfo-8.4.23-160000.1.1 * php8-shmop-8.4.23-160000.1.1 * php8-tidy-debuginfo-8.4.23-160000.1.1 * php8-pdo-debuginfo-8.4.23-160000.1.1 * php8-bcmath-debuginfo-8.4.23-160000.1.1 * php8-xsl-8.4.23-160000.1.1 * php8-gmp-8.4.23-160000.1.1 * php8-xmlwriter-8.4.23-160000.1.1 * php8-ldap-debuginfo-8.4.23-160000.1.1 * php8-openssl-debuginfo-8.4.23-160000.1.1 * php8-phar-debuginfo-8.4.23-160000.1.1 * php8-readline-8.4.23-160000.1.1 * php8-xsl-debuginfo-8.4.23-160000.1.1 * php8-opcache-debuginfo-8.4.23-160000.1.1 * php8-soap-debuginfo-8.4.23-160000.1.1 * php8-dom-8.4.23-160000.1.1 * php8-ctype-8.4.23-160000.1.1 * php8-posix-8.4.23-160000.1.1 * php8-mysql-debuginfo-8.4.23-160000.1.1 * php8-curl-8.4.23-160000.1.1 * php8-iconv-debuginfo-8.4.23-160000.1.1 * php8-sysvshm-debuginfo-8.4.23-160000.1.1 * php8-odbc-8.4.23-160000.1.1 * php8-tokenizer-debuginfo-8.4.23-160000.1.1 * php8-dom-debuginfo-8.4.23-160000.1.1 * php8-8.4.23-160000.1.1 * php8-tidy-8.4.23-160000.1.1 * php8-dba-8.4.23-160000.1.1 * apache2-mod_php8-8.4.23-160000.1.1 * php8-snmp-8.4.23-160000.1.1 * php8-readline-debuginfo-8.4.23-160000.1.1 * php8-sodium-8.4.23-160000.1.1 * php8-fastcgi-8.4.23-160000.1.1 * php8-exif-8.4.23-160000.1.1 * php8-gettext-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-debuginfo-8.4.23-160000.1.1 * php8-debuginfo-8.4.23-160000.1.1 * php8-devel-8.4.23-160000.1.1 * apache2-mod_php8-debuginfo-8.4.23-160000.1.1 * php8-phar-8.4.23-160000.1.1 * php8-enchant-debuginfo-8.4.23-160000.1.1 * php8-enchant-8.4.23-160000.1.1 * php8-calendar-8.4.23-160000.1.1 * php8-sqlite-8.4.23-160000.1.1 * php8-snmp-debuginfo-8.4.23-160000.1.1 * php8-sodium-debuginfo-8.4.23-160000.1.1 * php8-ldap-8.4.23-160000.1.1 * php8-ffi-debuginfo-8.4.23-160000.1.1 * php8-shmop-debuginfo-8.4.23-160000.1.1 * php8-fileinfo-debuginfo-8.4.23-160000.1.1 * php8-fpm-8.4.23-160000.1.1 * php8-xmlwriter-debuginfo-8.4.23-160000.1.1 * php8-pgsql-debuginfo-8.4.23-160000.1.1 * php8-ftp-debuginfo-8.4.23-160000.1.1 * php8-cli-8.4.23-160000.1.1 * php8-sockets-8.4.23-160000.1.1 * php8-ctype-debuginfo-8.4.23-160000.1.1 * php8-odbc-debuginfo-8.4.23-160000.1.1 * php8-pcntl-8.4.23-160000.1.1 * php8-pgsql-8.4.23-160000.1.1 * php8-cli-debuginfo-8.4.23-160000.1.1 * php8-dba-debuginfo-8.4.23-160000.1.1 * php8-intl-8.4.23-160000.1.1 * php8-fastcgi-debugsource-8.4.23-160000.1.1 * php8-mysql-8.4.23-160000.1.1 * php8-intl-debuginfo-8.4.23-160000.1.1 * php8-exif-debuginfo-8.4.23-160000.1.1 * php8-curl-debuginfo-8.4.23-160000.1.1 * php8-ftp-8.4.23-160000.1.1 * php8-ffi-8.4.23-160000.1.1 * php8-fastcgi-debuginfo-8.4.23-160000.1.1 * php8-gettext-8.4.23-160000.1.1 * php8-fpm-debugsource-8.4.23-160000.1.1 * php8-bcmath-8.4.23-160000.1.1 * php8-mbstring-8.4.23-160000.1.1 * php8-sqlite-debuginfo-8.4.23-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * php8-fpm-apache-8.4.23-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * php8-fpm-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-8.4.23-160000.1.1 * php8-iconv-8.4.23-160000.1.1 * php8-sysvmsg-8.4.23-160000.1.1 * php8-fileinfo-8.4.23-160000.1.1 * php8-pdo-8.4.23-160000.1.1 * php8-xmlreader-debuginfo-8.4.23-160000.1.1 * php8-gd-debuginfo-8.4.23-160000.1.1 * php8-gd-8.4.23-160000.1.1 * php8-tokenizer-8.4.23-160000.1.1 * php8-soap-8.4.23-160000.1.1 * php8-openssl-8.4.23-160000.1.1 * php8-sysvmsg-debuginfo-8.4.23-160000.1.1 * php8-zip-8.4.23-160000.1.1 * php8-xmlreader-8.4.23-160000.1.1 * php8-gmp-debuginfo-8.4.23-160000.1.1 * php8-sockets-debuginfo-8.4.23-160000.1.1 * php8-bz2-8.4.23-160000.1.1 * php8-embed-debuginfo-8.4.23-160000.1.1 * php8-mbstring-debuginfo-8.4.23-160000.1.1 * php8-zlib-debuginfo-8.4.23-160000.1.1 * php8-opcache-8.4.23-160000.1.1 * php8-calendar-debuginfo-8.4.23-160000.1.1 * php8-debugsource-8.4.23-160000.1.1 * php8-zlib-8.4.23-160000.1.1 * php8-sysvshm-8.4.23-160000.1.1 * php8-embed-8.4.23-160000.1.1 * php8-posix-debuginfo-8.4.23-160000.1.1 * php8-pcntl-debuginfo-8.4.23-160000.1.1 * php8-embed-debugsource-8.4.23-160000.1.1 * apache2-mod_php8-debugsource-8.4.23-160000.1.1 * php8-zip-debuginfo-8.4.23-160000.1.1 * php8-bz2-debuginfo-8.4.23-160000.1.1 * php8-shmop-8.4.23-160000.1.1 * php8-tidy-debuginfo-8.4.23-160000.1.1 * php8-xsl-8.4.23-160000.1.1 * php8-bcmath-debuginfo-8.4.23-160000.1.1 * php8-pdo-debuginfo-8.4.23-160000.1.1 * php8-gmp-8.4.23-160000.1.1 * php8-xmlwriter-8.4.23-160000.1.1 * php8-ldap-debuginfo-8.4.23-160000.1.1 * php8-openssl-debuginfo-8.4.23-160000.1.1 * php8-phar-debuginfo-8.4.23-160000.1.1 * php8-readline-8.4.23-160000.1.1 * php8-xsl-debuginfo-8.4.23-160000.1.1 * php8-opcache-debuginfo-8.4.23-160000.1.1 * php8-ctype-8.4.23-160000.1.1 * php8-dom-8.4.23-160000.1.1 * php8-soap-debuginfo-8.4.23-160000.1.1 * php8-posix-8.4.23-160000.1.1 * php8-mysql-debuginfo-8.4.23-160000.1.1 * php8-curl-8.4.23-160000.1.1 * php8-iconv-debuginfo-8.4.23-160000.1.1 * php8-sysvshm-debuginfo-8.4.23-160000.1.1 * php8-odbc-8.4.23-160000.1.1 * php8-tokenizer-debuginfo-8.4.23-160000.1.1 * php8-dom-debuginfo-8.4.23-160000.1.1 * php8-8.4.23-160000.1.1 * php8-tidy-8.4.23-160000.1.1 * php8-dba-8.4.23-160000.1.1 * apache2-mod_php8-8.4.23-160000.1.1 * php8-snmp-8.4.23-160000.1.1 * php8-readline-debuginfo-8.4.23-160000.1.1 * php8-sodium-8.4.23-160000.1.1 * php8-fastcgi-8.4.23-160000.1.1 * php8-exif-8.4.23-160000.1.1 * php8-gettext-debuginfo-8.4.23-160000.1.1 * php8-sysvsem-debuginfo-8.4.23-160000.1.1 * php8-debuginfo-8.4.23-160000.1.1 * php8-devel-8.4.23-160000.1.1 * apache2-mod_php8-debuginfo-8.4.23-160000.1.1 * php8-phar-8.4.23-160000.1.1 * php8-enchant-debuginfo-8.4.23-160000.1.1 * php8-enchant-8.4.23-160000.1.1 * php8-calendar-8.4.23-160000.1.1 * php8-sqlite-8.4.23-160000.1.1 * php8-snmp-debuginfo-8.4.23-160000.1.1 * php8-sodium-debuginfo-8.4.23-160000.1.1 * php8-ldap-8.4.23-160000.1.1 * php8-ffi-debuginfo-8.4.23-160000.1.1 * php8-shmop-debuginfo-8.4.23-160000.1.1 * php8-fileinfo-debuginfo-8.4.23-160000.1.1 * php8-fpm-8.4.23-160000.1.1 * php8-xmlwriter-debuginfo-8.4.23-160000.1.1 * php8-pgsql-debuginfo-8.4.23-160000.1.1 * php8-ftp-debuginfo-8.4.23-160000.1.1 * php8-sockets-8.4.23-160000.1.1 * php8-cli-8.4.23-160000.1.1 * php8-ctype-debuginfo-8.4.23-160000.1.1 * php8-odbc-debuginfo-8.4.23-160000.1.1 * php8-pcntl-8.4.23-160000.1.1 * php8-pgsql-8.4.23-160000.1.1 * php8-cli-debuginfo-8.4.23-160000.1.1 * php8-dba-debuginfo-8.4.23-160000.1.1 * php8-intl-8.4.23-160000.1.1 * php8-fastcgi-debugsource-8.4.23-160000.1.1 * php8-mysql-8.4.23-160000.1.1 * php8-intl-debuginfo-8.4.23-160000.1.1 * php8-exif-debuginfo-8.4.23-160000.1.1 * php8-curl-debuginfo-8.4.23-160000.1.1 * php8-ftp-8.4.23-160000.1.1 * php8-ffi-8.4.23-160000.1.1 * php8-fastcgi-debuginfo-8.4.23-160000.1.1 * php8-gettext-8.4.23-160000.1.1 * php8-fpm-debugsource-8.4.23-160000.1.1 * php8-bcmath-8.4.23-160000.1.1 * php8-mbstring-8.4.23-160000.1.1 * php8-sqlite-debuginfo-8.4.23-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * php8-fpm-apache-8.4.23-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12184.html * https://www.suse.com/security/cve/CVE-2026-14355.html * https://bugzilla.suse.com/show_bug.cgi?id=1270351 * https://bugzilla.suse.com/show_bug.cgi?id=1270712 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:35:21 -0000 Subject: SUSE-SU-2026:22631-1: important: Security update for gsasl Message-ID: <178421972193.660.13885348577409963077@1437f03ce14a> # Security update for gsasl Announcement ID: SUSE-SU-2026:22631-1 Release Date: 2026-07-10T14:19:59Z Rating: important References: * bsc#1268885 Cross-References: * CVE-2026-56968 CVSS scores: * CVE-2026-56968 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-56968 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56968 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-56968 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for gsasl fixes the following issue * CVE-2026-56968: improper sanitization of a short challenge in `_gsasl_ntlm_client_step` of the NTLM client can lead to memory disclosure (bsc#1268885). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1214=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1214=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgsasl18-2.2.1-160000.4.1 * gsasl-debugsource-2.2.1-160000.4.1 * gsasl-devel-2.2.1-160000.4.1 * gsasl-debuginfo-2.2.1-160000.4.1 * gsasl-2.2.1-160000.4.1 * libgsasl18-debuginfo-2.2.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * gsasl-lang-2.2.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgsasl18-2.2.1-160000.4.1 * gsasl-debugsource-2.2.1-160000.4.1 * gsasl-devel-2.2.1-160000.4.1 * gsasl-debuginfo-2.2.1-160000.4.1 * gsasl-2.2.1-160000.4.1 * libgsasl18-debuginfo-2.2.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * gsasl-lang-2.2.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56968.html * https://bugzilla.suse.com/show_bug.cgi?id=1268885 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:35:27 -0000 Subject: SUSE-SU-2026:22630-1: moderate: Security update for nghttp2 Message-ID: <178421972742.660.4113612050079411711@1437f03ce14a> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:22630-1 Release Date: 2026-07-10T13:25:42Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue * CVE-2026-58055: HTTP request/response smuggling via upgrade request with `Content-Length` (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1213=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1213=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libnghttp2-14-1.64.0-160000.4.1 * libnghttp2-devel-1.64.0-160000.4.1 * nghttp2-1.64.0-160000.4.1 * nghttp2-debuginfo-1.64.0-160000.4.1 * libnghttp2-14-debuginfo-1.64.0-160000.4.1 * nghttp2-debugsource-1.64.0-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libnghttp2-14-1.64.0-160000.4.1 * libnghttp2-devel-1.64.0-160000.4.1 * nghttp2-1.64.0-160000.4.1 * nghttp2-debuginfo-1.64.0-160000.4.1 * libnghttp2-14-debuginfo-1.64.0-160000.4.1 * nghttp2-debugsource-1.64.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:35:45 -0000 Subject: SUSE-SU-2026:22627-1: important: Security update for uriparser Message-ID: <178421974594.660.16985114540360009655@1437f03ce14a> # Security update for uriparser Announcement ID: SUSE-SU-2026:22627-1 Release Date: 2026-07-10T09:37:43Z Rating: important References: * bsc#1262999 * bsc#1264578 * bsc#1264579 Cross-References: * CVE-2026-42371 * CVE-2026-44927 * CVE-2026-44928 CVSS scores: * CVE-2026-42371 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42371 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42371 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44927 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-44927 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-44927 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44927 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-44928 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for uriparser fixes the following issues * CVE-2026-42371: numeric truncation in text range comparison when an application accepts URIs with a length in gigabytes (bsc#1262999). * CVE-2026-44927: truncation of `ptrdiff_t` to `int` in various places (bsc#1264578). * CVE-2026-44928: function family `EqualsUri` can misclassify two unequal URIs as equal (bsc#1264579). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1208=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1208=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * uriparser-debugsource-0.9.8-160000.5.1 * uriparser-0.9.8-160000.5.1 * liburiparser1-0.9.8-160000.5.1 * uriparser-doc-0.9.8-160000.5.1 * uriparser-debuginfo-0.9.8-160000.5.1 * liburiparser1-debuginfo-0.9.8-160000.5.1 * uriparser-devel-0.9.8-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * uriparser-debugsource-0.9.8-160000.5.1 * liburiparser1-0.9.8-160000.5.1 * uriparser-0.9.8-160000.5.1 * uriparser-doc-0.9.8-160000.5.1 * uriparser-debuginfo-0.9.8-160000.5.1 * liburiparser1-debuginfo-0.9.8-160000.5.1 * uriparser-devel-0.9.8-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42371.html * https://www.suse.com/security/cve/CVE-2026-44927.html * https://www.suse.com/security/cve/CVE-2026-44928.html * https://bugzilla.suse.com/show_bug.cgi?id=1262999 * https://bugzilla.suse.com/show_bug.cgi?id=1264578 * https://bugzilla.suse.com/show_bug.cgi?id=1264579 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:35:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:35:57 -0000 Subject: SUSE-SU-2026:22626-1: important: Security update for python-Pillow Message-ID: <178421975786.660.16484659199088217536@1437f03ce14a> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:22626-1 Release Date: 2026-07-10T09:37:43Z Rating: important References: * bsc#1270404 * bsc#1270409 * bsc#1270410 * bsc#1270411 * bsc#1270412 Cross-References: * CVE-2026-42311 * CVE-2026-54059 * CVE-2026-54060 * CVE-2026-55379 * CVE-2026-55380 CVSS scores: * CVE-2026-42311 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42311 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-42311 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42311 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-54059 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54059 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54060 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55379 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55380 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-42311: malicious PSD file processing can lead to arbitrary code execution (bsc#1270404). * CVE-2026-54059: crafted PCF font data can cause excessive memory allocation (bsc#1270409). * CVE-2026-54060: fonts can trigger excessive memory allocation during conversion or saving (bsc#1270410). * CVE-2026-55379: bypass of decompression bomb protection allows excessive memory allocation (bsc#1270411). * CVE-2026-55380: crafted `.gd` file can trigger excessive C-heap allocation when loaded (bsc#1270412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1207=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1207=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-Pillow-tk-11.3.0-160000.6.1 * python313-Pillow-11.3.0-160000.6.1 * python313-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debugsource-11.3.0-160000.6.1 * python313-Pillow-tk-debuginfo-11.3.0-160000.6.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-Pillow-tk-11.3.0-160000.6.1 * python313-Pillow-11.3.0-160000.6.1 * python313-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debuginfo-11.3.0-160000.6.1 * python-Pillow-debugsource-11.3.0-160000.6.1 * python313-Pillow-tk-debuginfo-11.3.0-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42311.html * https://www.suse.com/security/cve/CVE-2026-54059.html * https://www.suse.com/security/cve/CVE-2026-54060.html * https://www.suse.com/security/cve/CVE-2026-55379.html * https://www.suse.com/security/cve/CVE-2026-55380.html * https://bugzilla.suse.com/show_bug.cgi?id=1270404 * https://bugzilla.suse.com/show_bug.cgi?id=1270409 * https://bugzilla.suse.com/show_bug.cgi?id=1270410 * https://bugzilla.suse.com/show_bug.cgi?id=1270411 * https://bugzilla.suse.com/show_bug.cgi?id=1270412 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:36:03 -0000 Subject: SUSE-SU-2026:22625-1: important: Security update for yelp Message-ID: <178421976348.660.8945030093574469794@1437f03ce14a> # Security update for yelp Announcement ID: SUSE-SU-2026:22625-1 Release Date: 2026-07-10T09:31:14Z Rating: important References: * bsc#1269625 Cross-References: * CVE-2026-13601 CVSS scores: * CVE-2026-13601 ( SUSE ): 6.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-13601 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-13601 ( NVD ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for yelp fixes the following issue * CVE-2026-13601: overly permissive Content Security Policy allows host file disclosure via Flatpak applications (bsc#1269625). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1206=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1206=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * yelp-42.3-160000.3.1 * libyelp0-42.3-160000.3.1 * yelp-debuginfo-42.3-160000.3.1 * yelp-debugsource-42.3-160000.3.1 * libyelp0-debuginfo-42.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * yelp-lang-42.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * yelp-lang-42.3-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * yelp-42.3-160000.3.1 * libyelp0-42.3-160000.3.1 * yelp-debuginfo-42.3-160000.3.1 * yelp-debugsource-42.3-160000.3.1 * libyelp0-debuginfo-42.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13601.html * https://bugzilla.suse.com/show_bug.cgi?id=1269625 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:36:22 -0000 Subject: SUSE-SU-2026:22624-1: important: Security update for python-cryptography Message-ID: <178421978200.660.6825839059945669162@1437f03ce14a> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:22624-1 Release Date: 2026-07-10T09:12:46Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1205=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1205=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-cryptography-debuginfo-44.0.3-160000.4.1 * python-cryptography-debugsource-44.0.3-160000.4.1 * python313-cryptography-44.0.3-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-cryptography-debuginfo-44.0.3-160000.4.1 * python-cryptography-debugsource-44.0.3-160000.4.1 * python313-cryptography-44.0.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:36:29 -0000 Subject: SUSE-SU-2026:22623-1: important: Security update for perl-DBI Message-ID: <178421978943.660.5884844191500248867@1437f03ce14a> # Security update for perl-DBI Announcement ID: SUSE-SU-2026:22623-1 Release Date: 2026-07-10T09:10:39Z Rating: important References: * bsc#1271017 * bsc#1271018 Cross-References: * CVE-2026-14380 * CVE-2026-14740 CVSS scores: * CVE-2026-14380 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-14380 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14740 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-14740 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for perl-DBI fixes the following issues * CVE-2026-14380: unvalidated string eval interpolation of the Profile package name can lead to arbitrary Perl code execution (bsc#1271018). * CVE-2026-14740: one-byte out-of-bounds read when deleting an initial SQL comment line can lead to a process crash (bsc#1271017). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1204=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1204=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * perl-DBI-debugsource-1.647.0-160000.4.1 * perl-DBI-1.647.0-160000.4.1 * perl-DBI-debuginfo-1.647.0-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * perl-DBI-debugsource-1.647.0-160000.4.1 * perl-DBI-1.647.0-160000.4.1 * perl-DBI-debuginfo-1.647.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14380.html * https://www.suse.com/security/cve/CVE-2026-14740.html * https://bugzilla.suse.com/show_bug.cgi?id=1271017 * https://bugzilla.suse.com/show_bug.cgi?id=1271018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:36:43 -0000 Subject: SUSE-SU-2026:22622-1: important: Security update for agama Message-ID: <178421980309.660.3774668136067533581@1437f03ce14a> # Security update for agama Announcement ID: SUSE-SU-2026:22622-1 Release Date: 2026-07-10T09:03:03Z Rating: important References: * bsc#1270526 * bsc#1270602 * bsc#1270678 * bsc#1270784 * bsc#1270850 * bsc#1270891 * bsc#1270992 Cross-References: * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for agama fixes the following issues * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length in rust- openssl crate (bsc#1270602). * CVE-2026-41678: openssl: incorrect bounds assertion in aes key wrap in rust- openssl crate (bsc#1270678). * CVE-2026-41681: openssl: MdCtxRef::digest_final() writes past caller buffer with no length check in rust-openssl crate (bsc#1270784). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory in rust-openssl crate (bsc#1270850). * CVE-2026-42327: openssl: arbitrary code execution via specially crafted certificate in rust-openssl crate (bsc#1270526). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding in rust-openssl crate (bsc#1270891). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers in rust- openssl crate (bsc#1270992). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1203=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1203=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * agama-debuginfo-17+647.daf9950fc-160000.12.1 * agama-debugsource-17+647.daf9950fc-160000.12.1 * agama-scripts-17+647.daf9950fc-160000.12.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * agama-debuginfo-17+647.daf9950fc-160000.12.1 * agama-debugsource-17+647.daf9950fc-160000.12.1 * agama-scripts-17+647.daf9950fc-160000.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270526 * https://bugzilla.suse.com/show_bug.cgi?id=1270602 * https://bugzilla.suse.com/show_bug.cgi?id=1270678 * https://bugzilla.suse.com/show_bug.cgi?id=1270784 * https://bugzilla.suse.com/show_bug.cgi?id=1270850 * https://bugzilla.suse.com/show_bug.cgi?id=1270891 * https://bugzilla.suse.com/show_bug.cgi?id=1270992 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:36:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:36:49 -0000 Subject: SUSE-SU-2026:22621-1: important: Security update for sssd Message-ID: <178421980991.660.2622585210479359419@1437f03ce14a> # Security update for sssd Announcement ID: SUSE-SU-2026:22621-1 Release Date: 2026-07-10T08:58:36Z Rating: important References: * bsc#1270708 * bsc#1270709 Cross-References: * CVE-2026-14474 * CVE-2026-14476 CVSS scores: * CVE-2026-14474 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14474 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14476 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-14476 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for sssd fixes the following issues * CVE-2026-14474: sudo LDAP provider searches entire directory tree for sudoRole objects by default, enabling privilege escalation (bsc#1270709). * CVE-2026-14476: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass (bsc#1270708). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1201=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1201=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * sssd-ldap-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-2.10.2-160000.3.1 * sssd-kcm-debuginfo-2.10.2-160000.3.1 * sssd-ad-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-2.10.2-160000.3.1 * libsss_nss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-2.10.2-160000.3.1 * libipa_hbac0-2.10.2-160000.3.1 * libipa_hbac-devel-2.10.2-160000.3.1 * libsss_certmap0-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-debuginfo-2.10.2-160000.3.1 * sssd-ipa-2.10.2-160000.3.1 * sssd-krb5-common-debuginfo-2.10.2-160000.3.1 * sssd-kcm-2.10.2-160000.3.1 * libsss_idmap-devel-2.10.2-160000.3.1 * python3-ipa_hbac-2.10.2-160000.3.1 * libsss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-debuginfo-2.10.2-160000.3.1 * sssd-proxy-2.10.2-160000.3.1 * sssd-krb5-common-2.10.2-160000.3.1 * sssd-dbus-2.10.2-160000.3.1 * libnfsidmap-sss-2.10.2-160000.3.1 * python3-sss-murmur-2.10.2-160000.3.1 * sssd-tools-2.10.2-160000.3.1 * libsss_certmap0-2.10.2-160000.3.1 * sssd-dbus-debuginfo-2.10.2-160000.3.1 * sssd-ipa-debuginfo-2.10.2-160000.3.1 * sssd-debugsource-2.10.2-160000.3.1 * sssd-ldap-2.10.2-160000.3.1 * sssd-krb5-2.10.2-160000.3.1 * sssd-tools-debuginfo-2.10.2-160000.3.1 * libsss_idmap0-debuginfo-2.10.2-160000.3.1 * sssd-2.10.2-160000.3.1 * libsss_nss_idmap-devel-2.10.2-160000.3.1 * sssd-krb5-debuginfo-2.10.2-160000.3.1 * libsss_certmap-devel-2.10.2-160000.3.1 * sssd-debuginfo-2.10.2-160000.3.1 * sssd-proxy-debuginfo-2.10.2-160000.3.1 * libsss_nss_idmap0-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-debuginfo-2.10.2-160000.3.1 * python3-sss-murmur-debuginfo-2.10.2-160000.3.1 * libipa_hbac0-debuginfo-2.10.2-160000.3.1 * sssd-ad-2.10.2-160000.3.1 * libnfsidmap-sss-debuginfo-2.10.2-160000.3.1 * python3-ipa_hbac-debuginfo-2.10.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * sssd-ldap-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-2.10.2-160000.3.1 * sssd-kcm-debuginfo-2.10.2-160000.3.1 * sssd-ad-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-2.10.2-160000.3.1 * libsss_nss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-2.10.2-160000.3.1 * libipa_hbac0-2.10.2-160000.3.1 * libipa_hbac-devel-2.10.2-160000.3.1 * libsss_certmap0-debuginfo-2.10.2-160000.3.1 * sssd-winbind-idmap-debuginfo-2.10.2-160000.3.1 * sssd-ipa-2.10.2-160000.3.1 * libsss_idmap-devel-2.10.2-160000.3.1 * sssd-kcm-2.10.2-160000.3.1 * sssd-krb5-common-debuginfo-2.10.2-160000.3.1 * python3-ipa_hbac-2.10.2-160000.3.1 * libsss_idmap0-2.10.2-160000.3.1 * python3-sssd-config-debuginfo-2.10.2-160000.3.1 * sssd-proxy-2.10.2-160000.3.1 * sssd-krb5-common-2.10.2-160000.3.1 * sssd-dbus-2.10.2-160000.3.1 * python3-sss-murmur-2.10.2-160000.3.1 * libnfsidmap-sss-2.10.2-160000.3.1 * sssd-tools-2.10.2-160000.3.1 * libsss_certmap0-2.10.2-160000.3.1 * sssd-dbus-debuginfo-2.10.2-160000.3.1 * sssd-ipa-debuginfo-2.10.2-160000.3.1 * sssd-debugsource-2.10.2-160000.3.1 * sssd-ldap-2.10.2-160000.3.1 * sssd-krb5-2.10.2-160000.3.1 * sssd-tools-debuginfo-2.10.2-160000.3.1 * libsss_idmap0-debuginfo-2.10.2-160000.3.1 * libsss_nss_idmap-devel-2.10.2-160000.3.1 * sssd-krb5-debuginfo-2.10.2-160000.3.1 * sssd-2.10.2-160000.3.1 * libsss_certmap-devel-2.10.2-160000.3.1 * sssd-debuginfo-2.10.2-160000.3.1 * sssd-proxy-debuginfo-2.10.2-160000.3.1 * libsss_nss_idmap0-debuginfo-2.10.2-160000.3.1 * python3-sss-murmur-debuginfo-2.10.2-160000.3.1 * python3-sss_nss_idmap-debuginfo-2.10.2-160000.3.1 * libipa_hbac0-debuginfo-2.10.2-160000.3.1 * sssd-ad-2.10.2-160000.3.1 * libnfsidmap-sss-debuginfo-2.10.2-160000.3.1 * python3-ipa_hbac-debuginfo-2.10.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14474.html * https://www.suse.com/security/cve/CVE-2026-14476.html * https://bugzilla.suse.com/show_bug.cgi?id=1270708 * https://bugzilla.suse.com/show_bug.cgi?id=1270709 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:37:10 -0000 Subject: SUSE-SU-2026:22620-1: important: Security update for ImageMagick Message-ID: <178421983037.660.4015817331915173921@1437f03ce14a> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:22620-1 Release Date: 2026-07-10T08:56:16Z Rating: important References: * bsc#1268640 * bsc#1268878 * bsc#1270001 * bsc#1270002 * bsc#1270003 * bsc#1270073 * bsc#1270074 * bsc#1270077 * bsc#1270079 * bsc#1270080 * bsc#1271099 Cross-References: * CVE-2026-53466 * CVE-2026-53467 * CVE-2026-55594 * CVE-2026-55595 * CVE-2026-55597 * CVE-2026-56361 * CVE-2026-56363 * CVE-2026-56364 * CVE-2026-56374 * CVE-2026-56379 CVSS scores: * CVE-2026-53466 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-53466 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53466 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-53467 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53467 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53467 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55594 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-55594 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55594 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-55595 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55595 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55595 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-55597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55597 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-56361 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56361 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56361 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56361 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56363 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56363 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56363 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56363 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56364 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56364 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56364 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56374 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-56374 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56374 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56374 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-56374 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-56379 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-56379 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-56379 ( NVD ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56379 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56379 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities and has one fix can now be installed. ## Description: This update for ImageMagick fixes the following issues * CVE-2026-53466: integer overflow in the XCF decoder can result in an out-of- bounds read when a crafted image is read (bsc#1270073). * CVE-2026-53467: allocated memory left unchanged in the MNG decoder can lead to a heap information disclosure (bsc#1270074). * CVE-2026-55594: missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided (bsc#1270077). * CVE-2026-55595: providing invalid arguments to the `connected-components` option can lead to an infinite loop (bsc#1270079). * CVE-2026-55597: incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder (bsc#1270080). * CVE-2026-56361: off-by-one error in morphology validation can lead to an out-of-bounds read (bsc#1270001). * CVE-2026-56363: integer overflow leading to a division by zero in binomial kernel processing can cause an application crash (bsc#1270002). * CVE-2026-56364: memory leak in `LoadOpenCLDeviceBenchmark` function when parsing malformed OpenCL device profile XML files with unclosed device elements (bsc#1270003). * CVE-2026-56374: missing boundary checks can lead to a heap buffer overflow in the FTXT encoder when parsing `ftxt:format` (bsc#1271099). * CVE-2026-56379: arbitrary MVG drawing command injection via the SVG decoder when processing specially crafted SVG files (bsc#1268878). * GHSA-3j4x-rwrx-xxj9: possible use-after-free write in PDB decoder (bsc#1268640). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1202=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1202=1 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * ImageMagick-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-devel-7.1.2.0-160000.11.1 * ImageMagick-debugsource-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.11.1 * perl-PerlMagick-7.1.2.0-160000.11.1 * ImageMagick-devel-7.1.2.0-160000.11.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-debuginfo-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-extra-7.1.2.0-160000.11.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.11.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.11.1 * ImageMagick-doc-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.11.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.11.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * ImageMagick-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-devel-7.1.2.0-160000.11.1 * ImageMagick-debugsource-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.2.0-160000.11.1 * perl-PerlMagick-7.1.2.0-160000.11.1 * ImageMagick-devel-7.1.2.0-160000.11.1 * perl-PerlMagick-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-debuginfo-7.1.2.0-160000.11.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * ImageMagick-extra-7.1.2.0-160000.11.1 * ImageMagick-extra-debuginfo-7.1.2.0-160000.11.1 * libMagickWand-7_Q16HDRI10-debuginfo-7.1.2.0-160000.11.1 * libMagick++-7_Q16HDRI5-7.1.2.0-160000.11.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-limited-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-secure-7.1.2.0-160000.11.1 * ImageMagick-doc-7.1.2.0-160000.11.1 * ImageMagick-config-7-upstream-open-7.1.2.0-160000.11.1 * ImageMagick-config-7-SUSE-7.1.2.0-160000.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53466.html * https://www.suse.com/security/cve/CVE-2026-53467.html * https://www.suse.com/security/cve/CVE-2026-55594.html * https://www.suse.com/security/cve/CVE-2026-55595.html * https://www.suse.com/security/cve/CVE-2026-55597.html * https://www.suse.com/security/cve/CVE-2026-56361.html * https://www.suse.com/security/cve/CVE-2026-56363.html * https://www.suse.com/security/cve/CVE-2026-56364.html * https://www.suse.com/security/cve/CVE-2026-56374.html * https://www.suse.com/security/cve/CVE-2026-56379.html * https://bugzilla.suse.com/show_bug.cgi?id=1268640 * https://bugzilla.suse.com/show_bug.cgi?id=1268878 * https://bugzilla.suse.com/show_bug.cgi?id=1270001 * https://bugzilla.suse.com/show_bug.cgi?id=1270002 * https://bugzilla.suse.com/show_bug.cgi?id=1270003 * https://bugzilla.suse.com/show_bug.cgi?id=1270073 * https://bugzilla.suse.com/show_bug.cgi?id=1270074 * https://bugzilla.suse.com/show_bug.cgi?id=1270077 * https://bugzilla.suse.com/show_bug.cgi?id=1270079 * https://bugzilla.suse.com/show_bug.cgi?id=1270080 * https://bugzilla.suse.com/show_bug.cgi?id=1271099 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:37:25 -0000 Subject: SUSE-SU-2026:22617-1: important: Security update for xwayland Message-ID: <178421984515.660.4032658147544576709@1437f03ce14a> # Security update for xwayland Announcement ID: SUSE-SU-2026:22617-1 Release Date: 2026-07-10T08:53:56Z Rating: important References: * bsc#1268893 * bsc#1268894 Cross-References: * CVE-2026-55999 * CVE-2026-56000 CVSS scores: * CVE-2026-55999 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-55999 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-55999 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-56000 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56000 ( NVD ): 9.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56000 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for xwayland fixes the following issues * CVE-2026-55999: missing bounds check in `glamor_font_get` can lead to a heap buffer overflow when a font loaded from a malicious PCF file is processed (bsc#1268893). * CVE-2026-56000: improper memory management in `CommonMakeCurrent` can lead to a heap use-after-free when an interaction with a malicious client creating GLX contexts happens (bsc#1268894). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1194=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1194=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * xwayland-debuginfo-24.1.6-160000.6.1 * xwayland-debugsource-24.1.6-160000.6.1 * xwayland-24.1.6-160000.6.1 * xwayland-devel-24.1.6-160000.6.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * xwayland-devel-24.1.6-160000.6.1 * xwayland-debugsource-24.1.6-160000.6.1 * xwayland-debuginfo-24.1.6-160000.6.1 * xwayland-24.1.6-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55999.html * https://www.suse.com/security/cve/CVE-2026-56000.html * https://bugzilla.suse.com/show_bug.cgi?id=1268893 * https://bugzilla.suse.com/show_bug.cgi?id=1268894 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:37:32 -0000 Subject: SUSE-SU-2026:22616-1: important: Security update for tiff Message-ID: <178421985261.660.127125617307713584@1437f03ce14a> # Security update for tiff Announcement ID: SUSE-SU-2026:22616-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1268434 * bsc#1269779 Cross-References: * CVE-2026-12912 * CVE-2026-36849 * CVE-2026-4775 CVSS scores: * CVE-2026-12912 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-12912 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-36849 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-4775 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-4775 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-4775 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for tiff fixes the following issues * CVE-2026-12912: heap-based buffer overflow when processing crafted PixarLog- compressed TIFF image (bsc#1269779). * CVE-2026-36849: denial of service when processing a a crafted TIFF file containing a large SamplesPerPixel tag value (bsc#1268434). Changes for tiff: * Update to 4.7.2: Software configuration changes: * cmake: Fix bundle identifiers to use reverse-DNS format * cmake: Fix and improve Apple framework build support * cmake: Use TurboJPEG CONFIG by default (issue #767) * cmake: changes related to 8-/12-bit modes * cmake: Replace CMath::CMath with direct link to avoid export. * Support for iOS-derived builds * Simplify cmake byte order version check * Add additional warnings, primarily floating precision conversions and integer arithmetic conversions * configure.ac: Require bootstrap with at least Autoconf 2.71. Bug fixes: * Handle negative TIFFReadFile results before state updates (issue #854) * tif_dirread.c: fix copy-paste bug in ChopUpSingleUncompressedStrip * tif_read.c: Fixed division by zero in TIFFStartStrip() (issue #777) * tif_dirwrite.c: add integer overflow checks to allocation size calculations * tif_print.c: add integer overflow checks to allocation size calculations * tif_write.c: fix OOB read and underflow in TIFFAppendToStrip copy loop * DumpModeSeek: add bounds check to prevent OOB pointer advance * TIFFGrowStrips: fix use-after-free on partial realloc failure. * Fix NULL dereference in _TIFFReserveLargeEnoughWriteBuffer() by validating the strip bytecount array before accessing it. * TIFFRGBAImage: avoid int overflows in put functions (issue #830) * tif_getimage: fix inconsistent fromskew handling in put16bitbwtile (issue #792) * tif_getimage: Widen pointer-offset arithmetic in tif_getimage * putcontig8bitYCbCr44tile: fix wrong fromskew computation (issue #798) * putcontig8bitYCbCr42tile: Reject invalid YCbCr subsampling when image dimensions are smaller than the subsampling block to prevent out-of-bounds writes. (issue #753) * TIFFFillStrip/Tile(): avoid excessive memory allocation (issue #831) * TIFFLinkDirectory() checks for IFD loops (issue #788) * Check result of _TIFFCheckRealloc to prevent memory leaks and segmentation fault when reallocation fails. * TIFFVTileSize64(): in YCbCr contig non upsampled mode, validate td_samplesperpixel==3 (issue #805) * TIFFReadDirEntryPersampleShort(): be tolerant to tags like SampleFormat not having 1 or SamplesPerPixel values (https://github.com/OSGeo/gdal/issues/13465) * tif_getimage: reject tile widths that would overflow toskew (issue #808) * Fix integer overflow in _TIFFPartialReadStripArray on 32-bit. * TIFFAppendToStrip(): add some checks to avoid null-pointer-dereferencing (issue #777). * _TIFFGetStrileOffsetOrByteCountValue(): fix potential crash on corrupted files when file opened in 'O' mode (https://issues.oss- fuzz.com/issues/471328917) * TIFFReadDirectory(): re-set TIFF_LAZYSTRILELOAD if file opened in 'O' mode * _TIFFMergeFields(): avoid NULL ptr dereference (issue #755). * Check td_stripbytecount_p and td_stripoffset_p for NULL pointer before (re-)writing to file. (issue #749) * JPEGDecodeRaw: initialize output buffer to avoid returning uninitialized memory (issue #892) * JPEG decompressor: initialize output buffer when JPEG image is smaller than strile dimension to avoid heap memory disclosure (issue #826) * JPEG: fix generation of tiled 12-bit JPEG compressed files with libjpeg- turbo 3.0.3 (issue #773) * JPEGDecode(): fix memory leak in error code path (https://issues.oss- fuzz.com/issues/471945501) * tif_jpeg: reject mismatched JPEG data precision to avoid write overflow * Fix signed left-shift UB in LogLuv RANDITHER encoding (issue #850) * PixarLog: error out on invalid ABGR output buffer sizes. * PixarLog: complete ABGR bounds check for multi-row strip decoding. * PixarLog: fix undoing horizontal differencing when SamplesPerPixel != 3 and 4 (issue #789). * PixarLog codec: fix potential integer overflow/out-of-bounds access (issue #797) * TIFFAdvanceDirectory(): avoid potential read heap-buffer-overflow in mmap code path on 32 bit builds (https://issues.oss-fuzz.com/issues/506737072) * OJPEG: fix integer overflow in subsampling buffer allocation. * OJPEG: fix nullptr deref when changing compression method from OJPEG to something else (issue #795). * OJPEG fix potential integer overflow/out-of-bounds access (issue #796). * ojpeg: prevent EOF infinite loop (fixes commit 2a3d55b) * fix null pointer deference in issue #782. * fix stack-overflow in issue #784. Other changes: * Change EXIF and GPS tag type from IFD8 to LONG8 per EXIF-specification (issue #739). * Harden integer size and offset calculations (issue #897) * TIFFComputeTile/TIFFComputeStrip: use overflow-checked multiplication * Move widening casts inside multiplication scope. * Lots of compiler warning fixes related to enabling more warning flags * Align writing and reading of TIFF_LONG8 and TIFF_IFD8 tags (issue #773) * TIFFFillStrip(): prevent harmless unsigned integer overflow ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1200=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1200=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * tiff-4.7.2-160000.1.1 * tiff-debugsource-4.7.2-160000.1.1 * tiff-debuginfo-4.7.2-160000.1.1 * libtiff6-4.7.2-160000.1.1 * libtiff6-debuginfo-4.7.2-160000.1.1 * libtiff-devel-4.7.2-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * tiff-4.7.2-160000.1.1 * tiff-debugsource-4.7.2-160000.1.1 * tiff-debuginfo-4.7.2-160000.1.1 * libtiff6-4.7.2-160000.1.1 * libtiff6-debuginfo-4.7.2-160000.1.1 * libtiff-devel-4.7.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12912.html * https://www.suse.com/security/cve/CVE-2026-36849.html * https://www.suse.com/security/cve/CVE-2026-4775.html * https://bugzilla.suse.com/show_bug.cgi?id=1268434 * https://bugzilla.suse.com/show_bug.cgi?id=1269779 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:37:50 -0000 Subject: SUSE-SU-2026:22615-1: important: Security update for python-maturin Message-ID: <178421987037.660.5265331106777413008@1437f03ce14a> # Security update for python-maturin Announcement ID: SUSE-SU-2026:22615-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1270208 * bsc#1270515 * bsc#1270620 * bsc#1270706 * bsc#1270772 * bsc#1270801 * bsc#1270936 * bsc#1270994 Cross-References: * CVE-2026-41676 * CVE-2026-41677 * CVE-2026-41678 * CVE-2026-41681 * CVE-2026-41898 * CVE-2026-42327 * CVE-2026-44662 * CVE-2026-45784 CVSS scores: * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41677 ( SUSE ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U * CVE-2026-41677 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-41677 ( NVD ): 1.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41677 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-41678 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41678 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-41678 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41678 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41681 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41681 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-41681 ( NVD ): 8.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41681 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41898 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41898 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-41898 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41898 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42327 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42327 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-42327 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44662 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-44662 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-44662 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45784 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45784 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for python-maturin fixes the following issues * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270208). * CVE-2026-41677: openssl: out-of-bounds read in PEM password callback when returning an oversized length (bsc#1270620). * CVE-2026-41678: openssl: out-of-bounds write due to incorrect bounds assertion in `aes::unwrap_key()` (bsc#1270706). * CVE-2026-41681: openssl: `MdCtxRef::digest_final()` writes past caller buffer with no length check (bsc#1270772). * CVE-2026-41898: openssl: unchecked callback-returned length in PSK and cookie generate trampolines can leak adjacent memory to the network (bsc#1270801). * CVE-2026-42327: openssl: undefined behavior in `X509Ref::ocsp_responders` for certificates with non-UTF-8 OCSP URLs (bsc#1270515). * CVE-2026-44662: openssl: heap buffer overflow when encrypting with AES key- wrap-with-padding due to incorrectly sized output buffers (bsc#1270936). * CVE-2026-45784: openssl: out-of-bounds write in `CipherCtxRef::cipher_update_inplace` for AES-KW-PAD ciphers due to incorrectly sized output buffer (bsc#1270994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1196=1 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1196=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-maturin-1.8.7-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-maturin-1.8.7-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41676.html * https://www.suse.com/security/cve/CVE-2026-41677.html * https://www.suse.com/security/cve/CVE-2026-41678.html * https://www.suse.com/security/cve/CVE-2026-41681.html * https://www.suse.com/security/cve/CVE-2026-41898.html * https://www.suse.com/security/cve/CVE-2026-42327.html * https://www.suse.com/security/cve/CVE-2026-44662.html * https://www.suse.com/security/cve/CVE-2026-45784.html * https://bugzilla.suse.com/show_bug.cgi?id=1270208 * https://bugzilla.suse.com/show_bug.cgi?id=1270515 * https://bugzilla.suse.com/show_bug.cgi?id=1270620 * https://bugzilla.suse.com/show_bug.cgi?id=1270706 * https://bugzilla.suse.com/show_bug.cgi?id=1270772 * https://bugzilla.suse.com/show_bug.cgi?id=1270801 * https://bugzilla.suse.com/show_bug.cgi?id=1270936 * https://bugzilla.suse.com/show_bug.cgi?id=1270994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:37:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:37:59 -0000 Subject: SUSE-SU-2026:22614-1: important: Security update for libXfont2 Message-ID: <178421987913.660.13771232520976364024@1437f03ce14a> # Security update for libXfont2 Announcement ID: SUSE-SU-2026:22614-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1269018 * bsc#1269019 * bsc#1269020 Cross-References: * CVE-2026-56001 * CVE-2026-56002 * CVE-2026-56003 CVSS scores: * CVE-2026-56001 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56001 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56001 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56001 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56002 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56002 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56002 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56002 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56003 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56003 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-56003 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-56003 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for libXfont2 fixes the following issues * CVE-2026-56001: BitmapScaleBitmaps Integer Overflow Heap Buffer Overflow (bsc#1269018). * CVE-2026-56002: PCF Font Parsing Heap Buffer Overflow (bsc#1269019). * CVE-2026-56003: computeProps Property Buffer Heap Buffer Overflow (bsc#1269020). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1195=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1195=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libXfont2-debugsource-2.0.7-160000.4.1 * libXfont2-2-2.0.7-160000.4.1 * libXfont2-devel-2.0.7-160000.4.1 * libXfont2-2-debuginfo-2.0.7-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libXfont2-debugsource-2.0.7-160000.4.1 * libXfont2-2-2.0.7-160000.4.1 * libXfont2-devel-2.0.7-160000.4.1 * libXfont2-2-debuginfo-2.0.7-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56001.html * https://www.suse.com/security/cve/CVE-2026-56002.html * https://www.suse.com/security/cve/CVE-2026-56003.html * https://bugzilla.suse.com/show_bug.cgi?id=1269018 * https://bugzilla.suse.com/show_bug.cgi?id=1269019 * https://bugzilla.suse.com/show_bug.cgi?id=1269020 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:38:07 -0000 Subject: SUSE-SU-2026:22613-1: important: Security update for cosign Message-ID: <178421988750.660.14425874706842750494@1437f03ce14a> # Security update for cosign Announcement ID: SUSE-SU-2026:22613-1 Release Date: 2026-07-10T08:49:41Z Rating: important References: * bsc#1261811 * bsc#1266049 * bsc#1267044 Cross-References: * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33815 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 CVSS scores: * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33815 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-33815 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33815 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for cosign fixes the following issues * CVE-2026-25680,CVE-2026-25681,CVE-2026-27136,CVE-2026-42502,CVE-2026-42506: multiple issues when parsing HTML files (bsc#1267044). * CVE-2026-33815: memory-safety vulnerability (bsc#1261811). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831,CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508,CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: Fixed multiple issues in golang.org/x/crypto/ssh. (bsc#1266049). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1192=1 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1192=1 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cosign-debuginfo-3.1.1-160000.1.1 * cosign-3.1.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cosign-debuginfo-3.1.1-160000.1.1 * cosign-3.1.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33815.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://bugzilla.suse.com/show_bug.cgi?id=1261811 * https://bugzilla.suse.com/show_bug.cgi?id=1266049 * https://bugzilla.suse.com/show_bug.cgi?id=1267044 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:38:29 -0000 Subject: SUSE-SU-2026:3075-1: important: Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Message-ID: <178421990926.660.14169282290425528873@1437f03ce14a> # Security update for the Linux Kernel (Live Patch 15 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3075-1 Release Date: 2026-07-16T10:03:56Z Rating: important References: * bsc#1266015 * bsc#1266265 * bsc#1267206 * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-43501 * CVE-2026-45970 * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-46243 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-43501 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-43501 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-43501 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43501 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-45970 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46243 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46243 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.55 fixes various security issues The following security issues were fixed: * CVE-2026-43501: ipv6: rpl: reserve mac_len headroom when recompressed SRH grows (bsc#1266015). * CVE-2026-45970: bonding: alb: fix UAF in rlb_arp_recv during bond up/down (bsc#1267206). * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-46243: smb: client: reject userspace cifs.spnego descriptions (CIFSwitch) (bsc#1266265). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3075=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_55-default-2-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_15-debugsource-2-150700.2.2 * kernel-livepatch-6_4_0-150700_53_55-default-debuginfo-2-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-43501.html * https://www.suse.com/security/cve/CVE-2026-45970.html * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-46243.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1266015 * https://bugzilla.suse.com/show_bug.cgi?id=1266265 * https://bugzilla.suse.com/show_bug.cgi?id=1267206 * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 16:38:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 16:38:37 -0000 Subject: SUSE-SU-2026:3074-1: moderate: Security update for libssh2_org Message-ID: <178421991738.660.11574805939963271999@1437f03ce14a> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3074-1 Release Date: 2026-07-16T09:59:26Z Rating: moderate References: * bsc#1227490 * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for libssh2_org fixes the following issue Security changes: * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). Other changes: * rebuild libssh2_org against openssl 1.1.1, enabling ed25519 support. (bsc#1227490) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3074=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3074=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3074=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3074=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3074=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3074=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3074=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3074=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3074=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3074=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3074=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3074=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3074=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-1.11.0-150200.9.5.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libssh2-1-32bit-1.11.0-150200.9.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libssh2-1-1.11.0-150200.9.5.1 * libssh2_org-debugsource-1.11.0-150200.9.5.1 * libssh2-devel-1.11.0-150200.9.5.1 * libssh2-1-debuginfo-1.11.0-150200.9.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1227490 * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 20:30:34 -0000 Subject: SUSE-SU-2026:3078-1: moderate: Security update for rpcbind Message-ID: <178423383491.685.9257752556410365959@1437f03ce14a> # Security update for rpcbind Announcement ID: SUSE-SU-2026:3078-1 Release Date: 2026-07-16T15:54:38Z Rating: moderate References: * bsc#1267212 Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has one security fix can now be installed. ## Description: This update for rpcbind fixes the following issue * Fix several memory leaks and buffer overflow (bsc#1267212). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3078=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * rpcbind-0.2.3-24.12.1 * rpcbind-debugsource-0.2.3-24.12.1 * rpcbind-debuginfo-0.2.3-24.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 20:30:41 -0000 Subject: SUSE-SU-2026:3077-1: moderate: Security update for rpcbind Message-ID: <178423384188.685.5407010954428000649@1437f03ce14a> # Security update for rpcbind Announcement ID: SUSE-SU-2026:3077-1 Release Date: 2026-07-16T15:54:15Z Rating: moderate References: * bsc#1267212 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for rpcbind fixes the following issue * Fix several memory leaks and buffer overflow (bsc#1267212). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3077=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3077=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3077=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3077=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3077=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3077=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * rpcbind-debuginfo-0.2.3-150000.5.12.1 * rpcbind-debugsource-0.2.3-150000.5.12.1 * rpcbind-0.2.3-150000.5.12.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1267212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Jul 16 20:30:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 16 Jul 2026 20:30:47 -0000 Subject: SUSE-SU-2026:3076-1: moderate: Security update for libssh2_org Message-ID: <178423384792.685.17736548771274423288@1437f03ce14a> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3076-1 Release Date: 2026-07-16T13:04:25Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3076=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3076=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3076=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3076=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libssh2-1-64bit-1.11.0-150600.20.3.1 * libssh2-1-64bit-debuginfo-1.11.0-150600.20.3.1 * openSUSE Leap 15.6 (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libssh2-devel-1.11.0-150600.20.3.1 * libssh2-1-1.11.0-150600.20.3.1 * libssh2_org-debugsource-1.11.0-150600.20.3.1 * libssh2-1-debuginfo-1.11.0-150600.20.3.1 * Basesystem Module 15-SP7 (x86_64) * libssh2-1-32bit-1.11.0-150600.20.3.1 * libssh2-1-32bit-debuginfo-1.11.0-150600.20.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:30:19 -0000 Subject: SUSE-SU-2026:3083-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178427701944.28495.13443013083880028719@fcb35a5fe5ab> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:3083-1 Release Date: 2026-07-16T16:33:31Z Rating: important References: * bsc#1267698 * bsc#1267723 * bsc#1267893 * bsc#1268662 * bsc#1269023 * bsc#1269495 Cross-References: * CVE-2026-46120 * CVE-2026-46173 * CVE-2026-46227 * CVE-2026-52909 * CVE-2026-52943 * CVE-2026-53362 CVSS scores: * CVE-2026-46120 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46120 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46227 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53362 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53362 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.60 fixes various security issues The following security issues were fixed: * CVE-2026-46120: ip6_gre: Use cached t->net in ip6erspan_changelink() (bsc#1267893). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267723). * CVE-2026-46227: sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL (bsc#1267698). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268662). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269023). * CVE-2026-53362: ipv6: account for fraggap on the paged allocation path (bsc#1269495). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-3083=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_60-default-2-150700.2.2 * kernel-livepatch-6_4_0-150700_53_60-default-debuginfo-2-150700.2.2 * kernel-livepatch-SLE15-SP7_Update_16-debugsource-2-150700.2.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46120.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46227.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-53362.html * https://bugzilla.suse.com/show_bug.cgi?id=1267698 * https://bugzilla.suse.com/show_bug.cgi?id=1267723 * https://bugzilla.suse.com/show_bug.cgi?id=1267893 * https://bugzilla.suse.com/show_bug.cgi?id=1268662 * https://bugzilla.suse.com/show_bug.cgi?id=1269023 * https://bugzilla.suse.com/show_bug.cgi?id=1269495 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:30:32 -0000 Subject: SUSE-SU-2026:3088-1: moderate: Security update for tomcat Message-ID: <178427703200.28495.10972343843756606646@fcb35a5fe5ab> # Security update for tomcat Announcement ID: SUSE-SU-2026:3088-1 Release Date: 2026-07-16T17:59:44Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues Update to Tomcat 9.0.119. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 9.0.119: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Wrong references to jakarta instead of javax. (remm) * Fix: Restore default authenticator to nullafter executing an Ant task. (remm) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update Tomcat Native to 1.3.8. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3088=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat-el-3_0-api-9.0.119-150200.111.1 * tomcat-webapps-9.0.119-150200.111.1 * tomcat-lib-9.0.119-150200.111.1 * tomcat-jsp-2_3-api-9.0.119-150200.111.1 * tomcat-servlet-4_0-api-9.0.119-150200.111.1 * tomcat-admin-webapps-9.0.119-150200.111.1 * tomcat-9.0.119-150200.111.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:30:46 -0000 Subject: SUSE-SU-2026:3087-1: moderate: Security update for tomcat11 Message-ID: <178427704636.28495.9230865277763115397@fcb35a5fe5ab> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:3087-1 Release Date: 2026-07-16T17:56:56Z Rating: moderate References: * bsc#1232390 * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for tomcat11 fixes the following issues Update to Tomcat 11.0.23. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Upgrade libtcnative to v2 (bsc#1232390). * Tomcat 11.0.23: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Lower the log level to debug when OpenSSL initialization fails in OpenSSLLifecycleListener to avoid stack traces when libssl.so is not present and to align the behavior of the isAvailable() check with the AprLifecycleListener and gracefully fail when natives are not present. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix SSO cookie partitioned configuration. (remm) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Update default web.xml version to match supported Servlet specification version. (markt) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This us a breaking change for the EncryptInterceptor.(markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3087=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3087=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat11-11.0.23-150600.13.24.1 * tomcat11-el-6_0-api-11.0.23-150600.13.24.1 * tomcat11-servlet-6_1-api-11.0.23-150600.13.24.1 * tomcat11-lib-11.0.23-150600.13.24.1 * tomcat11-admin-webapps-11.0.23-150600.13.24.1 * tomcat11-jsp-4_0-api-11.0.23-150600.13.24.1 * tomcat11-webapps-11.0.23-150600.13.24.1 * openSUSE Leap 15.6 (noarch) * tomcat11-jsvc-11.0.23-150600.13.24.1 * tomcat11-docs-webapp-11.0.23-150600.13.24.1 * tomcat11-11.0.23-150600.13.24.1 * tomcat11-el-6_0-api-11.0.23-150600.13.24.1 * tomcat11-servlet-6_1-api-11.0.23-150600.13.24.1 * tomcat11-lib-11.0.23-150600.13.24.1 * tomcat11-admin-webapps-11.0.23-150600.13.24.1 * tomcat11-jsp-4_0-api-11.0.23-150600.13.24.1 * tomcat11-webapps-11.0.23-150600.13.24.1 * tomcat11-embed-11.0.23-150600.13.24.1 * tomcat11-doc-11.0.23-150600.13.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1232390 * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:30:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:30:53 -0000 Subject: SUSE-SU-2026:3086-1: important: Security update for python-python-socketio Message-ID: <178427705383.28495.16408475188274610173@fcb35a5fe5ab> # Security update for python-python-socketio Announcement ID: SUSE-SU-2026:3086-1 Release Date: 2026-07-16T17:53:06Z Rating: important References: * bsc#1269491 Cross-References: * CVE-2026-48804 CVSS scores: * CVE-2026-48804 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-python-socketio fixes the following issues: * CVE-2026-48804: Binary attachment accumulation can cause denial of service (bsc#1269491). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3086=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3086=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3086=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3086=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 * Python 3 Module 15-SP7 (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * python311-python-socketio-5.7.2-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48804.html * https://bugzilla.suse.com/show_bug.cgi?id=1269491 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:31:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:31:03 -0000 Subject: SUSE-SU-2026:3085-1: important: Security update for python-python-engineio Message-ID: <178427706374.28495.7901514191291850229@fcb35a5fe5ab> # Security update for python-python-engineio Announcement ID: SUSE-SU-2026:3085-1 Release Date: 2026-07-16T17:51:00Z Rating: important References: * bsc#1269544 * bsc#1269545 Cross-References: * CVE-2026-48802 * CVE-2026-48809 CVSS scores: * CVE-2026-48802 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48802 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48809 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48809 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-python-engineio fixes the following issues: * CVE-2026-48802: remote user can cause the creation of unnecessary background threads in the server through the heartbeat mechanism and cause a DoS (bsc#1269544). * CVE-2026-48809: size of incoming messages is not checked before they are loaded into memory and allows remote users to cause a DoS via excessive memory allocation (bsc#1269545). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3085=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3085=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3085=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3085=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 * Python 3 Module 15-SP7 (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * python311-python-engineio-4.3.4-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-48802.html * https://www.suse.com/security/cve/CVE-2026-48809.html * https://bugzilla.suse.com/show_bug.cgi?id=1269544 * https://bugzilla.suse.com/show_bug.cgi?id=1269545 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:31:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:31:19 -0000 Subject: SUSE-SU-2026:3084-1: moderate: Security update for python-Pillow Message-ID: <178427707982.28495.13764068346185682697@fcb35a5fe5ab> # Security update for python-Pillow Announcement ID: SUSE-SU-2026:3084-1 Release Date: 2026-07-16T17:46:49Z Rating: moderate References: * bsc#1271418 * bsc#1271419 * bsc#1271420 * bsc#1271421 * bsc#1271422 * bsc#1271424 * bsc#1271425 Cross-References: * CVE-2026-54058 * CVE-2026-59197 * CVE-2026-59198 * CVE-2026-59199 * CVE-2026-59200 * CVE-2026-59204 * CVE-2026-59205 CVSS scores: * CVE-2026-54058 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-54058 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-54058 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59197 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-59197 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59197 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-59198 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59198 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59198 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-59199 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59199 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59200 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59200 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59204 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59204 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59204 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59205 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59205 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for python-Pillow fixes the following issues * CVE-2026-54058: out-of-bounds read via attacker-controlled row stride on `mmap` path (bsc#1271419). * CVE-2026-59197: heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand` (bsc#1271418). * CVE-2026-59198: out-of-bounds heap data copied into file generated by TGA RLE encoder (bsc#1271420). * CVE-2026-59199: heap out-of-bounds write in `Image.paste()` and `Image.crop()` via signed coordinate overflow (bsc#1271421). * CVE-2026-59200: decompression bomb DoS via `PdfParser.PdfStream.decode()` (bsc#1271422). * CVE-2026-59204: denial of service through memory exhaustion via JPEG2000 tiled decoder (bsc#1271424). * CVE-2026-59205: controlled heap out-of-bounds write in `ImageCmsTransform.apply()` via output mode mismatch ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3084=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3084=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * python3-Pillow-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debuginfo-7.2.0-150300.3.30.1 * python3-Pillow-tk-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debugsource-7.2.0-150300.3.30.1 * python3-Pillow-7.2.0-150300.3.30.1 * python3-Pillow-tk-7.2.0-150300.3.30.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-Pillow-debuginfo-7.2.0-150300.3.30.1 * python-Pillow-debugsource-7.2.0-150300.3.30.1 * python-Pillow-debuginfo-7.2.0-150300.3.30.1 * python3-Pillow-7.2.0-150300.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54058.html * https://www.suse.com/security/cve/CVE-2026-59197.html * https://www.suse.com/security/cve/CVE-2026-59198.html * https://www.suse.com/security/cve/CVE-2026-59199.html * https://www.suse.com/security/cve/CVE-2026-59200.html * https://www.suse.com/security/cve/CVE-2026-59204.html * https://www.suse.com/security/cve/CVE-2026-59205.html * https://bugzilla.suse.com/show_bug.cgi?id=1271418 * https://bugzilla.suse.com/show_bug.cgi?id=1271419 * https://bugzilla.suse.com/show_bug.cgi?id=1271420 * https://bugzilla.suse.com/show_bug.cgi?id=1271421 * https://bugzilla.suse.com/show_bug.cgi?id=1271422 * https://bugzilla.suse.com/show_bug.cgi?id=1271424 * https://bugzilla.suse.com/show_bug.cgi?id=1271425 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 08:31:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 08:31:27 -0000 Subject: SUSE-SU-2026:3082-1: moderate: Security update for libssh2_org Message-ID: <178427708739.28495.4545730428149124782@fcb35a5fe5ab> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:3082-1 Release Date: 2026-07-16T16:17:33Z Rating: moderate References: * bsc#1268530 Cross-References: * CVE-2026-55199 CVSS scores: * CVE-2026-55199 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55199 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55199 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS An update that solves one vulnerability can now be installed. ## Description: This update for libssh2_org fixes the following issue * CVE-2026-55199: pre-Authentication DoS via SSH_MSG_EXT_INFO Handler (bsc#1268530). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3082=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3082=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3082=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh2-1-debuginfo-1.11.0-150000.4.32.1 * libssh2_org-debugsource-1.11.0-150000.4.32.1 * libssh2-1-32bit-1.11.0-150000.4.32.1 * libssh2-1-1.11.0-150000.4.32.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libssh2-1-debuginfo-1.11.0-150000.4.32.1 * libssh2-1-32bit-1.11.0-150000.4.32.1 * libssh2_org-debugsource-1.11.0-150000.4.32.1 * libssh2-1-1.11.0-150000.4.32.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libssh2-1-debuginfo-1.11.0-150000.4.32.1 * libssh2-1-32bit-1.11.0-150000.4.32.1 * libssh2_org-debugsource-1.11.0-150000.4.32.1 * libssh2-1-1.11.0-150000.4.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-55199.html * https://bugzilla.suse.com/show_bug.cgi?id=1268530 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 12:30:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 12:30:17 -0000 Subject: SUSE-SU-2026:3090-1: moderate: Security update for ruby3.4 Message-ID: <178429141770.832.3444936369087099825@178315a69387> # Security update for ruby3.4 Announcement ID: SUSE-SU-2026:3090-1 Release Date: 2026-07-17T06:13:22Z Rating: moderate References: * bsc#1268011 * bsc#1268337 * bsc#1268338 * bsc#1268339 * bsc#1270034 Cross-References: * CVE-2025-61594 * CVE-2026-42258 * CVE-2026-47240 * CVE-2026-47241 * CVE-2026-47242 CVSS scores: * CVE-2025-61594 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2025-61594 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-61594 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-42258 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-42258 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-42258 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42258 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L * CVE-2026-42258 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-47240 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-47240 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47241 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47241 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47242 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-47242 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for ruby3.4 fixes the following issues * CVE-2026-42258: Net:IMAP: Command Injection via Symbol Arguments (bsc#1268011). * CVE-2026-47240: Net:IMAP: Command Injection via non-synchronizing literal in "raw" argument (bsc#1268337). * CVE-2026-47241: Net:IMAP: Denial of Service via incomplete raw argument validation (bsc#1268338). * CVE-2026-47242: Net:IMAP: Command Injection via ID and ENABLE command arguments (bsc#1268339). * CVE-2025-61594: merging URIs using the + operator could expose sensitive user credentials (bsc#1270034). Changes for ruby3.4: * Update to 3.4.10: * bundling net-imap 0.5.15. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3090=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3090=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ruby3.4-devel-extra-3.4.10-150700.3.4.1 * ruby3.4-devel-3.4.10-150700.3.4.1 * ruby3.4-3.4.10-150700.3.4.1 * libruby3_4-3_4-3.4.10-150700.3.4.1 * ruby3.4-debugsource-3.4.10-150700.3.4.1 * ruby3.4-debuginfo-3.4.10-150700.3.4.1 * libruby3_4-3_4-debuginfo-3.4.10-150700.3.4.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ruby3.4-doc-3.4.10-150700.3.4.1 * ruby3.4-debugsource-3.4.10-150700.3.4.1 * ruby3.4-debuginfo-3.4.10-150700.3.4.1 * Development Tools Module 15-SP7 (noarch) * ruby3.4-doc-ri-3.4.10-150700.3.4.1 ## References: * https://www.suse.com/security/cve/CVE-2025-61594.html * https://www.suse.com/security/cve/CVE-2026-42258.html * https://www.suse.com/security/cve/CVE-2026-47240.html * https://www.suse.com/security/cve/CVE-2026-47241.html * https://www.suse.com/security/cve/CVE-2026-47242.html * https://bugzilla.suse.com/show_bug.cgi?id=1268011 * https://bugzilla.suse.com/show_bug.cgi?id=1268337 * https://bugzilla.suse.com/show_bug.cgi?id=1268338 * https://bugzilla.suse.com/show_bug.cgi?id=1268339 * https://bugzilla.suse.com/show_bug.cgi?id=1270034 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 12:31:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 12:31:06 -0000 Subject: SUSE-SU-2026:3089-1: important: Security update for the Linux Kernel Message-ID: <178429146656.832.12614196098275248218@178315a69387> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:3089-1 Release Date: 2026-07-17T01:35:33Z Rating: important References: * bsc#1264097 * bsc#1264145 * bsc#1265421 * bsc#1267381 * bsc#1267531 * bsc#1267567 * bsc#1267635 * bsc#1267684 * bsc#1267722 * bsc#1267918 * bsc#1267993 * bsc#1268022 * bsc#1268660 * bsc#1269022 * bsc#1269033 * bsc#1269036 * bsc#1269090 * bsc#1269100 * bsc#1269159 * bsc#1269184 * bsc#1269193 * bsc#1269195 * bsc#1269310 * bsc#1269398 * bsc#1269574 * bsc#1269678 * bsc#1269681 * bsc#1269821 * bsc#1270059 Cross-References: * CVE-2026-31771 * CVE-2026-43038 * CVE-2026-46090 * CVE-2026-46173 * CVE-2026-46197 * CVE-2026-46229 * CVE-2026-46253 * CVE-2026-46266 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-46320 * CVE-2026-46331 * CVE-2026-52909 * CVE-2026-52918 * CVE-2026-52923 * CVE-2026-52924 * CVE-2026-52943 * CVE-2026-52955 * CVE-2026-52969 * CVE-2026-52972 * CVE-2026-52993 * CVE-2026-53016 * CVE-2026-53041 * CVE-2026-53053 * CVE-2026-53071 * CVE-2026-53072 * CVE-2026-53133 * CVE-2026-53253 * CVE-2026-53359 CVSS scores: * CVE-2026-31771 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31771 ( SUSE ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-31771 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43038 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43038 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-46090 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46090 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46173 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46173 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46197 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46197 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46229 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46229 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46229 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46266 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46320 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46320 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46320 ( NVD ): 7.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-46331 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46331 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52909 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52909 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-52909 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( SUSE ): 8.6 CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52918 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52918 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-52924 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52924 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52924 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-52943 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52943 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52943 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52969 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52969 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52993 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52993 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52993 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53016 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53016 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53041 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53041 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53053 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53053 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53053 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53071 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53071 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53072 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53253 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53253 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53359 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53359 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 29 vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 15 SP5 kernel was updated to fix various security issues The following security issues were fixed: * CVE-2026-31771: Bluetooth: Ignore HCI_ERROR_CANCELLED_BY_HOST on adv set terminated event (bsc#1264145). * CVE-2026-43038: ipv6: icmp: clear skb2->cb in ip6_err_gen_icmpv6_unreach() (bsc#1264097). * CVE-2026-46090: ALSA: aloop: Fix peer runtime UAF during format-change stop (bsc#1267531). * CVE-2026-46173: exit: prevent preemption of oopsing TASK_DEAD task (bsc#1267722). * CVE-2026-46197: drm/amdkfd: validate SVM ioctl nattr against buffer size (bsc#1267381). * CVE-2026-46229: drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure (bsc#1267567). * CVE-2026-46253: pstore/ram: fix buffer overflow in persistent_ram_save_old() (bsc#1267635). * CVE-2026-46266: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP (bsc#1267684). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268022). * CVE-2026-46320: tap: free page on error paths in tap_get_user_xdp() (bsc#1267993). * CVE-2026-46331: net/sched: fix pedit partial COW leading to page cache (bsc#1265421). * CVE-2026-52909: ip6_vti: set netns_immutable on the fallback device (bsc#1268660). * CVE-2026-52918: Bluetooth: serialize accept_q access (bsc#1269100). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269033). * CVE-2026-52924: sctp: purge outqueue on stale COOKIE-ECHO handling (bsc#1269036). * CVE-2026-52943: net: skbuff: fix missing zerocopy reference in pskb_carve helpers (bsc#1269022). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-52969: KVM: Reject wrapped offset in kvm_reset_dirty_gfn() (bsc#1269184). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269195). * CVE-2026-52993: tipc: fix double-free in tipc_buf_append() (bsc#1269193). * CVE-2026-53016: crypto: ccp - copy IV using skcipher ivsize (bsc#1269090). * CVE-2026-53041: ocfs2: fix listxattr handling when the buffer is full (bsc#1269398). * CVE-2026-53053: iommu/amd: Fix clone_alias() to use the original device's devid (bsc#1269310). * CVE-2026-53071: Bluetooth: l2cap: Add missing chan lock in l2cap_ecred_reconf_rsp (bsc#1269678). * CVE-2026-53072: Bluetooth: fix locking in hci_conn_request_evt() with HCI_PROTO_DEFER (bsc#1269681). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269821). * CVE-2026-53253: Bluetooth: bnep: fix incorrect length parsing in bnep_rx_frame() extension handling (bsc#1269574). * CVE-2026-53359: KVM: x86: Fix shadow paging use-after-free due to unexpected role (bsc#1270059). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3089=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3089=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3089=1 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-3089=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3089=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3089=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3089=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * reiserfs-kmp-default-5.14.21-150500.55.177.1 * reiserfs-kmp-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * reiserfs-kmp-default-5.14.21-150500.55.177.1 * reiserfs-kmp-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64) * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (s390x) * kernel-zfcpdump-debugsource-5.14.21-150500.55.177.1 * kernel-zfcpdump-debuginfo-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (nosrc s390x) * kernel-zfcpdump-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * kernel-syms-5.14.21-150500.55.177.1 * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64) * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-default-debugsource-5.14.21-150500.55.177.1 * kernel-livepatch-5_14_21-150500_55_177-default-debuginfo-1-150500.11.5.1 * kernel-livepatch-SLE15-SP5_Update_43-debugsource-1-150500.11.5.1 * kernel-default-livepatch-5.14.21-150500.55.177.1 * kernel-livepatch-5_14_21-150500_55_177-default-1-150500.11.5.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-livepatch-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Live Patching 15-SP5 (nosrc) * kernel-default-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (nosrc s390x) * kernel-zfcpdump-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-5.14.21-150500.55.177.1 * reiserfs-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-optional-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-default-extra-5.14.21-150500.55.177.1 * kselftests-kmp-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * kernel-default-extra-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * kernel-obs-qa-5.14.21-150500.55.177.1 * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * kernel-default-optional-debuginfo-5.14.21-150500.55.177.1 * reiserfs-kmp-default-5.14.21-150500.55.177.1 * kernel-default-livepatch-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * kselftests-kmp-default-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64) * reiserfs-kmp-64kb-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * dtb-amazon-5.14.21-150500.55.177.1 * dtb-nvidia-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * dtb-mediatek-5.14.21-150500.55.177.1 * cluster-md-kmp-64kb-5.14.21-150500.55.177.1 * dtb-renesas-5.14.21-150500.55.177.1 * kselftests-kmp-64kb-5.14.21-150500.55.177.1 * reiserfs-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-allwinner-5.14.21-150500.55.177.1 * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-amlogic-5.14.21-150500.55.177.1 * dtb-socionext-5.14.21-150500.55.177.1 * kselftests-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-amd-5.14.21-150500.55.177.1 * dtb-broadcom-5.14.21-150500.55.177.1 * dtb-freescale-5.14.21-150500.55.177.1 * kernel-64kb-optional-debuginfo-5.14.21-150500.55.177.1 * dtb-rockchip-5.14.21-150500.55.177.1 * kernel-64kb-optional-5.14.21-150500.55.177.1 * dtb-xilinx-5.14.21-150500.55.177.1 * kernel-64kb-extra-debuginfo-5.14.21-150500.55.177.1 * dtb-sprd-5.14.21-150500.55.177.1 * dlm-kmp-64kb-5.14.21-150500.55.177.1 * dtb-arm-5.14.21-150500.55.177.1 * kernel-64kb-extra-5.14.21-150500.55.177.1 * dtb-apm-5.14.21-150500.55.177.1 * dtb-cavium-5.14.21-150500.55.177.1 * dtb-exynos-5.14.21-150500.55.177.1 * dtb-qcom-5.14.21-150500.55.177.1 * gfs2-kmp-64kb-5.14.21-150500.55.177.1 * cluster-md-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * dlm-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * gfs2-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-apple-5.14.21-150500.55.177.1 * ocfs2-kmp-64kb-debuginfo-5.14.21-150500.55.177.1 * dtb-marvell-5.14.21-150500.55.177.1 * dtb-hisilicon-5.14.21-150500.55.177.1 * dtb-altera-5.14.21-150500.55.177.1 * ocfs2-kmp-64kb-5.14.21-150500.55.177.1 * dtb-lg-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 ppc64le x86_64) * kernel-kvmsmall-devel-5.14.21-150500.55.177.1 * kernel-kvmsmall-debuginfo-5.14.21-150500.55.177.1 * kernel-kvmsmall-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * kernel-default-base-rebuild-5.14.21-150500.55.177.1.150500.6.83.2 * kernel-kvmsmall-debugsource-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_177-default-debuginfo-1-150500.11.5.1 * kernel-livepatch-SLE15-SP5_Update_43-debugsource-1-150500.11.5.1 * kernel-livepatch-5_14_21-150500_55_177-default-1-150500.11.5.1 * kernel-default-livepatch-devel-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (nosrc) * dtb-aarch64-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (x86_64) * kernel-kvmsmall-vdso-debuginfo-5.14.21-150500.55.177.1 * kernel-default-vdso-5.14.21-150500.55.177.1 * kernel-kvmsmall-vdso-5.14.21-150500.55.177.1 * kernel-default-vdso-debuginfo-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-docs-html-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * kernel-source-vanilla-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (aarch64 nosrc ppc64le x86_64) * kernel-kvmsmall-5.14.21-150500.55.177.1 * openSUSE Leap 15.5 (s390x) * kernel-zfcpdump-debugsource-5.14.21-150500.55.177.1 * kernel-zfcpdump-debuginfo-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-devel-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * kernel-default-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-debugsource-5.14.21-150500.55.177.1 * gfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-obs-build-5.14.21-150500.55.177.1 * ocfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-devel-5.14.21-150500.55.177.1 * cluster-md-kmp-default-debuginfo-5.14.21-150500.55.177.1 * dlm-kmp-default-debuginfo-5.14.21-150500.55.177.1 * ocfs2-kmp-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-debuginfo-5.14.21-150500.55.177.1 * cluster-md-kmp-default-5.14.21-150500.55.177.1 * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 * dlm-kmp-default-5.14.21-150500.55.177.1 * kernel-syms-5.14.21-150500.55.177.1 * gfs2-kmp-default-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 nosrc) * kernel-64kb-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch nosrc) * kernel-docs-5.14.21-150500.55.177.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64) * kernel-64kb-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-debugsource-5.14.21-150500.55.177.1 * kernel-64kb-devel-debuginfo-5.14.21-150500.55.177.1 * kernel-64kb-devel-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * kernel-macros-5.14.21-150500.55.177.1 * kernel-source-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * kernel-default-debuginfo-5.14.21-150500.55.177.1 * kernel-default-debugsource-5.14.21-150500.55.177.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64) * kernel-default-base-5.14.21-150500.55.177.1.150500.6.83.2 ## References: * https://www.suse.com/security/cve/CVE-2026-31771.html * https://www.suse.com/security/cve/CVE-2026-43038.html * https://www.suse.com/security/cve/CVE-2026-46090.html * https://www.suse.com/security/cve/CVE-2026-46173.html * https://www.suse.com/security/cve/CVE-2026-46197.html * https://www.suse.com/security/cve/CVE-2026-46229.html * https://www.suse.com/security/cve/CVE-2026-46253.html * https://www.suse.com/security/cve/CVE-2026-46266.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-46320.html * https://www.suse.com/security/cve/CVE-2026-46331.html * https://www.suse.com/security/cve/CVE-2026-52909.html * https://www.suse.com/security/cve/CVE-2026-52918.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52924.html * https://www.suse.com/security/cve/CVE-2026-52943.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-52969.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-52993.html * https://www.suse.com/security/cve/CVE-2026-53016.html * https://www.suse.com/security/cve/CVE-2026-53041.html * https://www.suse.com/security/cve/CVE-2026-53053.html * https://www.suse.com/security/cve/CVE-2026-53071.html * https://www.suse.com/security/cve/CVE-2026-53072.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53253.html * https://www.suse.com/security/cve/CVE-2026-53359.html * https://bugzilla.suse.com/show_bug.cgi?id=1264097 * https://bugzilla.suse.com/show_bug.cgi?id=1264145 * https://bugzilla.suse.com/show_bug.cgi?id=1265421 * https://bugzilla.suse.com/show_bug.cgi?id=1267381 * https://bugzilla.suse.com/show_bug.cgi?id=1267531 * https://bugzilla.suse.com/show_bug.cgi?id=1267567 * https://bugzilla.suse.com/show_bug.cgi?id=1267635 * https://bugzilla.suse.com/show_bug.cgi?id=1267684 * https://bugzilla.suse.com/show_bug.cgi?id=1267722 * https://bugzilla.suse.com/show_bug.cgi?id=1267918 * https://bugzilla.suse.com/show_bug.cgi?id=1267993 * https://bugzilla.suse.com/show_bug.cgi?id=1268022 * https://bugzilla.suse.com/show_bug.cgi?id=1268660 * https://bugzilla.suse.com/show_bug.cgi?id=1269022 * https://bugzilla.suse.com/show_bug.cgi?id=1269033 * https://bugzilla.suse.com/show_bug.cgi?id=1269036 * https://bugzilla.suse.com/show_bug.cgi?id=1269090 * https://bugzilla.suse.com/show_bug.cgi?id=1269100 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269184 * https://bugzilla.suse.com/show_bug.cgi?id=1269193 * https://bugzilla.suse.com/show_bug.cgi?id=1269195 * https://bugzilla.suse.com/show_bug.cgi?id=1269310 * https://bugzilla.suse.com/show_bug.cgi?id=1269398 * https://bugzilla.suse.com/show_bug.cgi?id=1269574 * https://bugzilla.suse.com/show_bug.cgi?id=1269678 * https://bugzilla.suse.com/show_bug.cgi?id=1269681 * https://bugzilla.suse.com/show_bug.cgi?id=1269821 * https://bugzilla.suse.com/show_bug.cgi?id=1270059 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:10 -0000 Subject: SUSE-SU-2026:3101-1: moderate: Security update for python-idna Message-ID: <178430581017.924.686964708689244646@1437f03ce14a> # Security update for python-idna Announcement ID: SUSE-SU-2026:3101-1 Release Date: 2026-07-17T11:42:14Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3101=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3101=1 ## Package List: * Public Cloud Module 12 (noarch) * python3-idna-2.5-3.16.1 * python-idna-2.5-3.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python3-idna-2.5-3.16.1 * python-idna-2.5-3.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:18 -0000 Subject: SUSE-SU-2026:3100-1: moderate: Security update for python-idna Message-ID: <178430581818.924.2124726185657767079@1437f03ce14a> # Security update for python-idna Announcement ID: SUSE-SU-2026:3100-1 Release Date: 2026-07-17T11:42:01Z Rating: moderate References: * bsc#1265413 Cross-References: * CVE-2026-45409 CVSS scores: * CVE-2026-45409 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-45409 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-45409 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-45409 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-idna fixes the following issue * CVE-2026-45409: specially crafted inputs to idna.encode() can bypass earlier security fix (bsc#1265413). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3100=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3100=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3100=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3100=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3100=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3100=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * python3-idna-2.6-150000.3.9.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * python3-idna-2.6-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45409.html * https://bugzilla.suse.com/show_bug.cgi?id=1265413 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:24 -0000 Subject: SUSE-SU-2026:3099-1: moderate: Security update for dash Message-ID: <178430582417.924.12070638374002908338@1437f03ce14a> # Security update for dash Announcement ID: SUSE-SU-2026:3099-1 Release Date: 2026-07-17T11:40:37Z Rating: moderate References: * bsc#1269494 Cross-References: * CVE-2026-31323 CVSS scores: * CVE-2026-31323 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31323 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for dash fixes the following issues * CVE-2026-31323: arithmetic expansion evaluating INTMAX_MIN / -1 can lead to a signed integer overflow and a denial of service (bsc#1269494). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3099=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dash-debugsource-0.5.11.2-150000.3.9.1 * dash-0.5.11.2-150000.3.9.1 * dash-debuginfo-0.5.11.2-150000.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-31323.html * https://bugzilla.suse.com/show_bug.cgi?id=1269494 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:32 -0000 Subject: SUSE-SU-2026:3098-1: important: Security update for shibboleth-sp Message-ID: <178430583236.924.5136507261516075505@1437f03ce14a> # Security update for shibboleth-sp Announcement ID: SUSE-SU-2026:3098-1 Release Date: 2026-07-17T11:40:03Z Rating: important References: * bsc#1249394 Cross-References: * CVE-2025-9943 CVSS scores: * CVE-2025-9943 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-9943 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for shibboleth-sp fixes the following issue: * CVE-2025-9943: SQL injection in the "ID" attribute of the SAML response when the replay cache of the Shibboleth Service Provider (SP) is configured to use an SQL database as storage service (bsc#1249394). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3098=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3098=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libshibsp-lite6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-debugsource-2.5.5-6.9.1 * libshibsp6-2.5.5-6.9.1 * shibboleth-sp-devel-2.5.5-6.9.1 * libshibsp6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-2.5.5-6.9.1 * libshibsp-lite6-2.5.5-6.9.1 * shibboleth-sp-debuginfo-2.5.5-6.9.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libshibsp6-2.5.5-6.9.1 * libshibsp-lite6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-debugsource-2.5.5-6.9.1 * shibboleth-sp-devel-2.5.5-6.9.1 * libshibsp6-debuginfo-2.5.5-6.9.1 * shibboleth-sp-2.5.5-6.9.1 * libshibsp-lite6-2.5.5-6.9.1 * shibboleth-sp-debuginfo-2.5.5-6.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9943.html * https://bugzilla.suse.com/show_bug.cgi?id=1249394 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:39 -0000 Subject: SUSE-SU-2026:3097-1: important: Security update for libxml2 Message-ID: <178430583935.924.1773886242220887819@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3097-1 Release Date: 2026-07-17T11:39:38Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3097=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3097=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libxml2-tools-2.12.10-150700.4.14.1 * libxml2-devel-2.12.10-150700.4.14.1 * python3-libxml2-debuginfo-2.12.10-150700.4.14.1 * libxml2-2-2.12.10-150700.4.14.1 * libxml2-debugsource-2.12.10-150700.4.14.1 * libxml2-python-debugsource-2.12.10-150700.4.14.1 * libxml2-2-debuginfo-2.12.10-150700.4.14.1 * libxml2-tools-debuginfo-2.12.10-150700.4.14.1 * python3-libxml2-2.12.10-150700.4.14.1 * Basesystem Module 15-SP7 (x86_64) * libxml2-2-32bit-debuginfo-2.12.10-150700.4.14.1 * libxml2-2-32bit-2.12.10-150700.4.14.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-libxml2-2.12.10-150700.4.14.1 * libxml2-python-debugsource-2.12.10-150700.4.14.1 * python311-libxml2-debuginfo-2.12.10-150700.4.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:46 -0000 Subject: SUSE-SU-2026:3096-1: important: Security update for libxml2 Message-ID: <178430584661.924.17590702520134935264@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3096-1 Release Date: 2026-07-17T11:39:17Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3096=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3096=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3096=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3096=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3096=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3096=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3096=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3096=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (x86_64) * libxml2-devel-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (noarch) * libxml2-doc-2.10.3-150500.5.41.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.10.3-150500.5.41.1 * libxml2-2-64bit-2.10.3-150500.5.41.1 * libxml2-devel-64bit-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libxml2-2-32bit-2.10.3-150500.5.41.1 * libxml2-2-32bit-debuginfo-2.10.3-150500.5.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libxml2-python-debugsource-2.10.3-150500.5.41.1 * python311-libxml2-2.10.3-150500.5.41.1 * python311-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-debugsource-2.10.3-150500.5.41.1 * libxml2-2-2.10.3-150500.5.41.1 * libxml2-devel-2.10.3-150500.5.41.1 * python3-libxml2-2.10.3-150500.5.41.1 * libxml2-2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-debuginfo-2.10.3-150500.5.41.1 * python3-libxml2-debuginfo-2.10.3-150500.5.41.1 * libxml2-tools-2.10.3-150500.5.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:30:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:30:54 -0000 Subject: SUSE-SU-2026:3095-1: important: Security update for libxml2 Message-ID: <178430585424.924.15641266360610062271@1437f03ce14a> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3095-1 Release Date: 2026-07-17T11:38:38Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3095=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3095=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3095=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3095=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3095=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3095=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3095=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3095=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3095=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libxml2-2-64bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-64bit-2.9.14-150400.5.58.1 * libxml2-devel-64bit-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (noarch) * libxml2-doc-2.9.14-150400.5.58.1 * openSUSE Leap 15.4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * libxml2-devel-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-python-debugsource-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libxml2-devel-2.9.14-150400.5.58.1 * python3-libxml2-2.9.14-150400.5.58.1 * libxml2-debugsource-2.9.14-150400.5.58.1 * python311-libxml2-2.9.14-150400.5.58.1 * libxml2-2-debuginfo-2.9.14-150400.5.58.1 * python3-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-tools-debuginfo-2.9.14-150400.5.58.1 * python311-libxml2-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-2.9.14-150400.5.58.1 * libxml2-tools-2.9.14-150400.5.58.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libxml2-2-32bit-debuginfo-2.9.14-150400.5.58.1 * libxml2-2-32bit-2.9.14-150400.5.58.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:31:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:31:03 -0000 Subject: SUSE-SU-2026:3094-1: moderate: Security update for openssl-3 Message-ID: <178430586301.924.4678467927593276581@1437f03ce14a> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:3094-1 Release Date: 2026-07-17T09:54:11Z Rating: moderate References: * bsc#1266344 * bsc#1266350 Cross-References: * CVE-2026-34182 * CVE-2026-42767 CVSS scores: * CVE-2026-34182 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34182 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-34182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42767 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42767 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42767 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for openssl-3 fixes the following issues * CVE-2026-34182: CMS AuthEnvelopedData Processing May Accept Forged Messages (bsc#1266344). * CVE-2026-42767: NULL Pointer Dereference in CRMF EncryptedValue Decryption (bsc#1266350). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3094=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3094=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3094=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3094=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3094=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3094=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3094=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3094=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3094=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (x86_64) * libopenssl3-32bit-3.0.8-150400.4.90.1 * libopenssl-3-devel-32bit-3.0.8-150400.4.90.1 * libopenssl3-32bit-debuginfo-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libopenssl3-64bit-3.0.8-150400.4.90.1 * libopenssl3-64bit-debuginfo-3.0.8-150400.4.90.1 * libopenssl-3-devel-64bit-3.0.8-150400.4.90.1 * openSUSE Leap 15.4 (noarch) * openssl-3-doc-3.0.8-150400.4.90.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libopenssl-3-devel-3.0.8-150400.4.90.1 * openssl-3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * openssl-3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.90.1 * libopenssl3-3.0.8-150400.4.90.1 * libopenssl3-debuginfo-3.0.8-150400.4.90.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34182.html * https://www.suse.com/security/cve/CVE-2026-42767.html * https://bugzilla.suse.com/show_bug.cgi?id=1266344 * https://bugzilla.suse.com/show_bug.cgi?id=1266350 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 16:31:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 16:31:10 -0000 Subject: SUSE-SU-2026:3093-1: moderate: Security update for python-paramiko Message-ID: <178430587048.924.5220247358561957527@1437f03ce14a> # Security update for python-paramiko Announcement ID: SUSE-SU-2026:3093-1 Release Date: 2026-07-17T09:48:50Z Rating: moderate References: * bsc#1264225 Cross-References: * CVE-2026-44405 CVSS scores: * CVE-2026-44405 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-44405 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-44405 ( NVD ): 3.4 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-paramiko fixes the following issue * CVE-2026-44405: data integrity compromise due to allowed SHA-1 algorithm use (bsc#1264225). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3093=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3093=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python-paramiko-doc-3.4.0-150400.13.13.1 * python311-paramiko-3.4.0-150400.13.13.1 * Public Cloud Module 15-SP4 (noarch) * python-paramiko-doc-3.4.0-150400.13.13.1 * python311-paramiko-3.4.0-150400.13.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44405.html * https://bugzilla.suse.com/show_bug.cgi?id=1264225 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:07 -0000 Subject: SUSE-SU-2026:3117-1: moderate: Security update for python-dulwich Message-ID: <178432020768.935.10105495015370009891@f4f3e2688bac> # Security update for python-dulwich Announcement ID: SUSE-SU-2026:3117-1 Release Date: 2026-07-17T15:37:51Z Rating: moderate References: * bsc#1268138 Cross-References: * CVE-2026-47734 CVSS scores: * CVE-2026-47734 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47734 ( NVD ): 5.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-dulwich fixes the following issue * CVE-2026-47734: Unbounded memory allocation in receive-pack from crafted thin packs (bsc#1268138). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-3117=1 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * python-dulwich-0.18.5-4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-47734.html * https://bugzilla.suse.com/show_bug.cgi?id=1268138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:13 -0000 Subject: SUSE-SU-2026:3116-1: moderate: Security update for libqt4 Message-ID: <178432021347.935.15230125956171056777@f4f3e2688bac> # Security update for libqt4 Announcement ID: SUSE-SU-2026:3116-1 Release Date: 2026-07-17T15:36:06Z Rating: moderate References: * bsc#1265896 Cross-References: * CVE-2025-14575 CVSS scores: * CVE-2025-14575 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-14575 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2025-14575 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libqt4 fixes the following issue * CVE-2025-14575: local user can load rogue CA certificates as trusted system authority via a crafted file placed in the application's working directory (bsc#1265896). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3116=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libqt4-x11-debuginfo-4.8.7-8.25.1 * libqt4-sql-plugins-debugsource-4.8.7-8.25.1 * libqt4-devel-4.8.7-8.25.1 * libqt4-sql-4.8.7-8.25.1 * libqt4-sql-mysql-debuginfo-4.8.7-8.25.1 * libqt4-sql-32bit-4.8.7-8.25.1 * qt4-x11-tools-4.8.7-8.25.1 * libqt4-x11-4.8.7-8.25.1 * libqt4-sql-mysql-4.8.7-8.25.1 * libqt4-qt3support-4.8.7-8.25.1 * libqt4-private-headers-devel-4.8.7-8.25.1 * libqt4-qt3support-32bit-4.8.7-8.25.1 * libqt4-x11-debuginfo-32bit-4.8.7-8.25.1 * qt4-x11-tools-debuginfo-4.8.7-8.25.1 * libqt4-sql-sqlite-debuginfo-4.8.7-8.25.1 * libqt4-qt3support-debuginfo-32bit-4.8.7-8.25.1 * libqt4-debuginfo-32bit-4.8.7-8.25.1 * libqt4-sql-debuginfo-4.8.7-8.25.1 * libqt4-debuginfo-4.8.7-8.25.1 * libqt4-sql-sqlite-4.8.7-8.25.1 * libqt4-4.8.7-8.25.1 * libqt4-devel-debuginfo-4.8.7-8.25.1 * libqt4-devel-doc-debugsource-4.8.7-8.25.1 * libqt4-devel-doc-4.8.7-8.25.1 * libqt4-32bit-4.8.7-8.25.1 * libqt4-sql-debuginfo-32bit-4.8.7-8.25.1 * libqt4-devel-doc-debuginfo-4.8.7-8.25.1 * libqt4-qt3support-debuginfo-4.8.7-8.25.1 * libqt4-debugsource-4.8.7-8.25.1 * libqt4-x11-32bit-4.8.7-8.25.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libqt4-devel-doc-data-4.8.7-8.25.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14575.html * https://bugzilla.suse.com/show_bug.cgi?id=1265896 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:21 -0000 Subject: SUSE-SU-2026:3115-1: moderate: Security update for vorbis-tools Message-ID: <178432022164.935.11606371383370498810@f4f3e2688bac> # Security update for vorbis-tools Announcement ID: SUSE-SU-2026:3115-1 Release Date: 2026-07-17T15:35:12Z Rating: moderate References: * bsc#1265361 Cross-References: * CVE-2026-34253 CVSS scores: * CVE-2026-34253 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34253 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for vorbis-tools fixes the following issue * CVE-2026-34253: buffer underflow in the `ogg123` utility in function `remotethread` of `remote.c` (bsc#1265361). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3115=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * vorbis-tools-debuginfo-1.4.0-150000.3.6.1 * vorbis-tools-debugsource-1.4.0-150000.3.6.1 * vorbis-tools-1.4.0-150000.3.6.1 * Desktop Applications Module 15-SP7 (noarch) * vorbis-tools-lang-1.4.0-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34253.html * https://bugzilla.suse.com/show_bug.cgi?id=1265361 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:27 -0000 Subject: SUSE-SU-2026:3114-1: moderate: Security update for vorbis-tools Message-ID: <178432022777.935.3087546591146117283@f4f3e2688bac> # Security update for vorbis-tools Announcement ID: SUSE-SU-2026:3114-1 Release Date: 2026-07-17T15:34:10Z Rating: moderate References: * bsc#1265361 Cross-References: * CVE-2026-34253 CVSS scores: * CVE-2026-34253 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-34253 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34253 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for vorbis-tools fixes the following issue * CVE-2026-34253: buffer underflow in the `ogg123` utility in function `remotethread` of `remote.c` (bsc#1265361). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3114=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * vorbis-tools-debugsource-1.4.0-27.6.1 * vorbis-tools-1.4.0-27.6.1 * vorbis-tools-debuginfo-1.4.0-27.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * vorbis-tools-lang-1.4.0-27.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-34253.html * https://bugzilla.suse.com/show_bug.cgi?id=1265361 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:33 -0000 Subject: SUSE-SU-2026:3113-1: important: Security update for python-msgpack Message-ID: <178432023376.935.8565310197719615112@f4f3e2688bac> # Security update for python-msgpack Announcement ID: SUSE-SU-2026:3113-1 Release Date: 2026-07-17T14:24:43Z Rating: important References: * bsc#1269947 Cross-References: * CVE-2026-57585 CVSS scores: * CVE-2026-57585 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57585 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-msgpack fixes the following issue * CVE-2026-57585: `Unpacker` reuse after a caught error can lead to an out-of- bounds read and a crash (bsc#1269947). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3113=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3113=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3113=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3113=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3113=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3113=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3113=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3113=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3113=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3113=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3113=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3113=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3113=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3113=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3113=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3113=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 * python3-msgpack-0.5.6-150100.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python3-msgpack-0.5.6-150100.3.6.1 * python-msgpack-debuginfo-0.5.6-150100.3.6.1 * python3-msgpack-debuginfo-0.5.6-150100.3.6.1 * python-msgpack-debugsource-0.5.6-150100.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57585.html * https://bugzilla.suse.com/show_bug.cgi?id=1269947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:47 -0000 Subject: SUSE-SU-2026:3112-1: moderate: Security update for tomcat10 Message-ID: <178432024727.935.10288631160446921872@f4f3e2688bac> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:3112-1 Release Date: 2026-07-17T14:20:26Z Rating: moderate References: * bsc#1269791 * bsc#1269824 * bsc#1269907 * bsc#1269908 * bsc#1269909 * bsc#1269910 Cross-References: * CVE-2026-50229 * CVE-2026-53404 * CVE-2026-53434 * CVE-2026-55276 * CVE-2026-55955 * CVE-2026-55956 CVSS scores: * CVE-2026-50229 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-50229 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-50229 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-53404 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53404 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53404 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-53434 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-53434 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-53434 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55276 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55276 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55276 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-55955 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55955 ( SUSE ): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55955 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-55956 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-55956 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues Update to Tomcat 10.1.56. Security issues fixed: * CVE-2026-50229: improper neutralization of script-related HTML tags in the number guess example (bsc#1269791). * CVE-2026-53404: always-incorrect control flow implementation in the rewrite valve caused non-OR conditions to be skipped if the first condition in an OR chain matched (bsc#1269910). * CVE-2026-53434: error condition not handled when configuring CRLs for a FFM based connector (bsc#1269824). * CVE-2026-55276: always-incorrect control flow implementation caused special roles and empty authorization constraints to not be included when the effective web.xml was logged (bsc#1269909). * CVE-2026-55955: improper authentication allows a replay attack against the EncryptionInterceptor in the cluster component (bsc#1269908). * CVE-2026-55956: improper authorization leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint (bsc#1269907). Other updates and bugfixes: * Tomcat 10.1.56: * Catalina * Add: Add support for literal '%' characters in access log output. Based on pull request #1002 by Fabian Hahn. (markt) * Fix: Prevent duplicate log messages when clustering JARs are not present on startup. (csutherl) * Fix: 70038: Cookie.clone() should also clone the internal attribute map. (markt) * Code: Remove unnecessary code from the SSI processing engine that was duplicating some of the normalisation checks. (markt) * Fix: Cleaner handling of invalid SPNEGO tokens. (remm) * Fix: Avoid some NPEs in the Connector class on an uninitialize protocol. (remm) * Fix: Incorrect session average life calculation. (remm) * Fix: Improve robustness on using Pipeline.setBasic on a running pipeline. (remm) * Fix: Avoid any init parameter updates when conflicts are found for filters, similar to what is done for servlets, as required by the servlet specification. (remm) * Fix: Fix container event cleanups in some edge cases. (remm) * Fix: Check for last-modified header in ExpiresFilter when a servlet uses addDateHeader to avoid wrongly considering it has been set. (remm) * Fix: Fix hour unit used by ExpiresFilter. (remm) * Fix: Remove exception swallowing in DataSourceStore to align it with FileStore and avoid session loss on errors. (remm) * Fix: Add support for single-quote escaped literal as well as quoted literals in DateFormatCache. (schultz) * Fix: On JAAS logout, clear out role principals on the subject that were added on commit, as recommended by the JAAS specification. (remm) * Fix: MemoryRealm should not add a dummy role when none is specified in the configuration. (remm) * Fix: DataSourceUserDatabase should return a null principal on a non existing user. (remm) * Fix: Fix shared lock expiration in WebDAV. (remm) * Fix: Inaccurate session exipration statistics when using the persistent manager. (remm) * Fix: Skip BOM when serving files with UTF-32 encoding. (remm) * Fix: Mixup of WrapperListener and WrapperLifecycle elements in storeconfig. (remm) * Fix: Incorrect processing of modified users in DataSourceUserDatabase. (remm) * Update: Clarify behavior in the UserDatabase for user, role and group creation that it does not immediately override existing elements. Removal (or update) needs to be used instead. (remm) * Fix: 70049: Align the web application class loader with parent class loaders and swallow any errors caused by invalid paths when looking up resources and behave as if the resources were not found in that case. (markt) * Fix: Improve validation of Range and Content-Range parsers so invalid ranges trigger a 4xx response rather than a 500 response. Pull request #1012 provided by Sahana Surendra Bogar. (markt) * Fix: Fix connection leak in ProxyErrorReportValve. (remm) * Fix: When using the RewriteValve, %{SSL:HTTPS} now returns on or off rather than true or false to align with httpd. (markt) * Fix: Reset the encoding used for query string parameters between requests in case an application changed the encoding in a previous request. (markt) * Fix: When encoding URLs with the CsrfPreventionFilter, don't add the nonce to URLs that are known not to require it. (markt) * Fix: Fix CombinedRealm isAvailable, it allows authentication if at least one sub realm is available. (remm) * Fix: 70048: Correctly handle asynchronous requests in PersistentValve. (markt) * Fix: Improve the detection of cross-context dispatches when using a RequestDispatcher. (markt) * Fix: Fix various instances of double decoding of URL patterns configured either programmatically or in web.xml. (remm/markt) * Fix: Align the rewrite conditions ornext flag processing with mod_rewrite, which follows a purely sequential evaluation strategy. (remm) * Fix: Change the default for the useRedirect attribute of the ProxyErrorReportValve from true to false. (markt) * Add: Add support for the showReport attribute in JsonErrorReportValve and ProxyErrorReportValve. When set to false, detailed error information (message, description, stack trace) is suppressed from error responses. (dsoumis) * Fix: Avoid a NoClassDefFoundError at startup when catalina-tribes.jar is removed but catalina-ha.jar is present and the Cluster element is enabled in server.xml. Cluster digester rules are now fully conditional on both JARs being available. (dsoumis) * Fix: Fix a potential deadlock when copying resources using WebDAV. (markt) * Fix: Add jakarta., org.apache.catalina. and org.apache.tomcat.to the list of reserved prefixes for SSI variables and request attributes. (markt) * Fix: Missing URL decoding when processing addMapping on a Servlet registration. (remm) * Fix: The Timeout WebDAV header allows comma separated values (according to the examples in the RFC). Use the first acceptable value. (remm) * Fix: Fix various issues when logging the effective web.xml for a web application. Empty sections are no longer logged. Special roles and empty authorisation constraints are included. All session cookie attributes are included. (markt) * Fix: Expand the write lock for the save process in the MemoryUserDatabase to avoid concurrency issues with the file save operations. (markt) * Fix: Ensure atomic session persistence in FileStore. Based on pull request #1016 by sahvx655-wq. (markt) * Fix: Do not ignore methods configured on security constraints that map to the default servlet. (markt) * Cluster * Fix: Expand wording and increase visibility of log message when cloud membership is configured without a trust store as all certificates will be trusted in this configuration. (markt) * Fix: Ensure listeners are correctly added and removed when configuring the channel coordinator. (markt) * Fix: Fix some concurrency issues in FragmentationInterceptor. (markt) * Fix: Fix some concurrency issues in OrderInterceptor. (markt) * Fix: Fix some concurrency issues in TwoPhaseCommitInterceptor. (markt) * Fix: Fix concurrency issues generating MD5 digests in the CloudMembershipProvider implementations. (markt) * Add: Add replay protection to the EncryptInterceptor. This is a breaking change for the EncryptInterceptor. (markt) * Coyote * Add: Log a suitable warning if an encrypted PEM file is detected using an insecure form for encryption. (markt) * Fix: If TLS groups have been configured, use the configured groups rather than using OpenSSL's default TLS groups when using Tomcat Native with OpenSSL based connectors. (markt) * Fix: For HTTP/2, ensure that any in progress request body reads are cancelled if the container resets the associated stream. This prevents delays waiting for reads to time out when it is known that no more data will be received. (markt) * Fix: Ensure that malformed HTTP/2 messages that should trigger a stream reset do so, rather than triggered a connection close. (markt) * Fix: Improve enforcement of header trailer allow list for HTTP/2. (remm) * Fix: 70050: Avoid NPE when no header frame is processed in HTTP/2, following refactor clean-up of header buffer. (remm) * Fix: Properly use pollerThreadPriority for the NIO poller thread. (remm) * Fix: Fix MessageByte.equals if called on a null MB. (remm) * Fix: Call the delegate key manager in JSSE to retrieve the server key. (remm) * Fix: Avoid overflow scenarios in Asn1Parser. (remm) * Fix: 70091: Add a new attribute, allowSchemeMismatch to Http2Protocol that allows the consistency check for the scheme provided by the user agent to be bypassed. (markt) * Fix: isTrailerFieldsReady was always returning true. (remm) * Fix: Align OpenSSL/Panama TLS implementation with other implementations and throw an exception if there is an error loading the provided CRL(s). (markt) * Fix: Parsing of OpenSSL format cipher expressions incorrectly stopped if @STRENGTH was encountered, ignoring any subsequent expressions. (markt) * Fix: Handle the case where the HTTP/2 payload length is insufficient for the mandatory data required by the flags set in the header. (markt) * Fix: 70102: Correct expected size of ticket keys when calling setSessionTicketKeys with an FFM connector. (markt) * Fix: 69988: Fix post handshake authentication for TLS 1.3. It was broken by a breaking change in OpenSSL between 1.1.1 and 3.0.0. (markt) * Fix: When processing an OpenSSL cipher specification, fully align the order of the resulting ciphers with the order produced by OpenSSL. (markt) * Add: Add support for Brainpool TLS groups. Patch provided by YStankov. (schultz) * Update: Update both the minimum and recommended version for Tomcat Native 2.x to 2.0.15. (markt) * Update: Update the minimum version for Tomcat Native 1.x to 1.3.8. (markt) * Jasper * Fix: Fix possible EL argument mismatch when it was set to null. (remm) * Fix: Fix thread safety of TagPluginManager. (remm) * Fix: Correctly use flush on JSP include. (remm) * Web applications * Add: Manager: Add checks to ensure that any uploaded files are uploaded to the expected location. (markt) * Add: Manager: Add checks to ensure that the requested context path for a deployed WAR, directory or descriptor file is valid. (markt) * Add: Documentation: Expand the description of some of the attributes of the CrawlerSessionManagerValve. (markt) * Fix: Documentation: Clearer description and correct documented default for ocspSoftFail. (markt) * Fix: Fix double escaping in the context names for the JSON mode of the manager servlet. (remm) * Fix: Manager: Ensure automatic deployment does not trigger an undeployment during a Manager triggered web application reload. (markt) * Fix: Documentation: Provide better documentation for the scheme and secure attributes of a Connector. (markt) * Websocket * Fix: Incorrect Future.isDone() return by AsyncChannelWrapperSecure. (remm) * Fix: Trigger standard WebSocket error handling if a call to Endpoint.onOpen() fails for a programmatic endpoint. (markt) * Fix: 70110: Fix memory leak if a call to Endpoint.onOpen() fails for a programmatic endpoint. Test case provided by uabdur. (markt) * Fix: If a client presents invalid parameters when negotiating a WebSocket extension, decline the negotiation offer that includes the invalid parameters rather than failing the connection. Pull request #1019 provided by sahvx655-wq. (markt) * Other * Fix: Use per connection authenticator when executing an Ant task. (remm/markt) * Update: Update Commons Daemon to 1.6.1. (markt) * Update: Improvements to French translations. (remm) * Update: Improvements to Japanese translations provided by tak7iji. (markt) * Update: Update the packaged version of the Tomcat Migration Tool for Jakarta EE to 1.0.12. (markt) * Update: Update Tomcat Native to 2.0.15. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3112=1 ## Package List: * Web and Scripting Module 15-SP7 (noarch) * tomcat10-admin-webapps-10.1.56-150200.5.70.1 * tomcat10-lib-10.1.56-150200.5.70.1 * tomcat10-webapps-10.1.56-150200.5.70.1 * tomcat10-jsp-3_1-api-10.1.56-150200.5.70.1 * tomcat10-el-5_0-api-10.1.56-150200.5.70.1 * tomcat10-servlet-6_0-api-10.1.56-150200.5.70.1 * tomcat10-10.1.56-150200.5.70.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50229.html * https://www.suse.com/security/cve/CVE-2026-53404.html * https://www.suse.com/security/cve/CVE-2026-53434.html * https://www.suse.com/security/cve/CVE-2026-55276.html * https://www.suse.com/security/cve/CVE-2026-55955.html * https://www.suse.com/security/cve/CVE-2026-55956.html * https://bugzilla.suse.com/show_bug.cgi?id=1269791 * https://bugzilla.suse.com/show_bug.cgi?id=1269824 * https://bugzilla.suse.com/show_bug.cgi?id=1269907 * https://bugzilla.suse.com/show_bug.cgi?id=1269908 * https://bugzilla.suse.com/show_bug.cgi?id=1269909 * https://bugzilla.suse.com/show_bug.cgi?id=1269910 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:30:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:30:52 -0000 Subject: SUSE-SU-2026:3111-1: important: Security update for libxml2 Message-ID: <178432025293.935.12060032737290752895@f4f3e2688bac> # Security update for libxml2 Announcement ID: SUSE-SU-2026:3111-1 Release Date: 2026-07-17T14:18:02Z Rating: important References: * bsc#1269790 Cross-References: * CVE-2026-11979 CVSS scores: * CVE-2026-11979 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-11979 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11979 ( NVD ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11979 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libxml2 fixes the following issue * CVE-2026-11979: stack-based buffer overflows in the `xmlcatalog` utility when running in `--shell` mode (bsc#1269790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3111=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3111=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libxml2-tools-2.9.4-46.102.2 * python-libxml2-debuginfo-2.9.4-46.102.2 * libxml2-tools-debuginfo-2.9.4-46.102.2 * libxml2-devel-2.9.4-46.102.2 * libxml2-2-debuginfo-2.9.4-46.102.2 * libxml2-2-2.9.4-46.102.2 * python-libxml2-debugsource-2.9.4-46.102.2 * libxml2-debugsource-2.9.4-46.102.2 * python-libxml2-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libxml2-2-32bit-2.9.4-46.102.2 * libxml2-2-debuginfo-32bit-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * libxml2-doc-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libxml2-2-debuginfo-32bit-2.9.4-46.102.2 * libxml2-tools-2.9.4-46.102.2 * python-libxml2-debuginfo-2.9.4-46.102.2 * libxml2-tools-debuginfo-2.9.4-46.102.2 * libxml2-2-2.9.4-46.102.2 * libxml2-devel-2.9.4-46.102.2 * libxml2-2-debuginfo-2.9.4-46.102.2 * libxml2-2-32bit-2.9.4-46.102.2 * python-libxml2-debugsource-2.9.4-46.102.2 * libxml2-debugsource-2.9.4-46.102.2 * python-libxml2-2.9.4-46.102.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libxml2-doc-2.9.4-46.102.2 ## References: * https://www.suse.com/security/cve/CVE-2026-11979.html * https://bugzilla.suse.com/show_bug.cgi?id=1269790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:31:00 -0000 Subject: SUSE-SU-2026:3110-1: important: Security update for mariadb-connector-c Message-ID: <178432026028.935.18126932913084967372@f4f3e2688bac> # Security update for mariadb-connector-c Announcement ID: SUSE-SU-2026:3110-1 Release Date: 2026-07-17T14:15:40Z Rating: important References: * bsc#1266438 Cross-References: * CVE-2026-44172 CVSS scores: * CVE-2026-44172 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-44172 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for mariadb-connector-c fixes the following issue: * CVE-2026-44172: mysql_real_escape_string() incorrectly handled big5 (bsc#1266438). Changes for mariadb-connector-c: * Update to 3.1.28. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3110=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3110=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3110=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3110=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3110=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * openSUSE Leap 15.6 (x86_64) * libmariadb3-32bit-3.1.28-150600.18.3.1 * libmariadb3-32bit-debuginfo-3.1.28-150600.18.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libmariadb3-64bit-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-64bit-3.1.28-150600.18.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libmariadb3-debuginfo-3.1.28-150600.18.3.1 * libmariadb3-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 * libmariadbprivate-3.1.28-150600.18.3.1 * libmariadbprivate-debuginfo-3.1.28-150600.18.3.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libmariadb_plugins-debuginfo-3.1.28-150600.18.3.1 * libmariadb-devel-3.1.28-150600.18.3.1 * libmariadb-devel-debuginfo-3.1.28-150600.18.3.1 * libmariadb_plugins-3.1.28-150600.18.3.1 * mariadb-connector-c-debugsource-3.1.28-150600.18.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44172.html * https://bugzilla.suse.com/show_bug.cgi?id=1266438 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:31:07 -0000 Subject: SUSE-SU-2026:3108-1: important: Security update for joe Message-ID: <178432026742.935.6005230046474368309@f4f3e2688bac> # Security update for joe Announcement ID: SUSE-SU-2026:3108-1 Release Date: 2026-07-17T14:12:50Z Rating: important References: * bsc#1269379 Cross-References: * CVE-2026-13412 CVSS scores: * CVE-2026-13412 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-13412 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for joe fixes the following issue * CVE-2026-13412: arbitrary command execution via malicious tags file (bsc#1269379). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3108=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * joe-debuginfo-4.4-150000.3.3.1 * joe-4.4-150000.3.3.1 * joe-debugsource-4.4-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13412.html * https://bugzilla.suse.com/show_bug.cgi?id=1269379 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:31:29 -0000 Subject: SUSE-SU-2026:3105-1: important: Security update for php-composer2 Message-ID: <178432028990.935.8721642185166003051@f4f3e2688bac> # Security update for php-composer2 Announcement ID: SUSE-SU-2026:3105-1 Release Date: 2026-07-17T13:32:58Z Rating: important References: * bsc#1271122 * bsc#1271129 * bsc#1271151 * bsc#1271504 Cross-References: * CVE-2024-35241 * CVE-2024-35242 * CVE-2025-67746 * CVE-2026-40176 * CVE-2026-40261 * CVE-2026-45793 * CVE-2026-59946 * CVE-2026-59947 * CVE-2026-59948 CVSS scores: * CVE-2024-35241 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-35241 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-35242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2024-35242 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-67746 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-67746 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-67746 ( NVD ): 1.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-67746 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40176 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40176 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40261 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40261 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-40261 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-45793 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-45793 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59946 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59946 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-59946 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59947 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59947 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59947 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59948 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59948 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59948 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for php-composer2 fixes the following issues: * CVE-2026-45793: Github Actions issued `GITHUB_TOKEN` disclosure in GitHub Actions logs (bsc#1271504). * CVE-2026-59946: path traversal in package `bin` field lets dependencies `chmod` arbitrary host files (bsc#1271151). * CVE-2026-59947: URL-embedded HTTP-Basic username leaks to verbose logs (bsc#1271129). * CVE-2026-59948: arbitrary file write outside `vendor`directory via malicious transitive package name (bsc#1271122). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3105=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3105=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3105=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3105=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * php-composer2-2.6.4-150600.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * php-composer2-2.6.4-150600.3.12.1 * Web and Scripting Module 15-SP7 (noarch) * php-composer2-2.6.4-150600.3.12.1 * openSUSE Leap 15.6 (noarch) * php-composer2-2.6.4-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35241.html * https://www.suse.com/security/cve/CVE-2024-35242.html * https://www.suse.com/security/cve/CVE-2025-67746.html * https://www.suse.com/security/cve/CVE-2026-40176.html * https://www.suse.com/security/cve/CVE-2026-40261.html * https://www.suse.com/security/cve/CVE-2026-45793.html * https://www.suse.com/security/cve/CVE-2026-59946.html * https://www.suse.com/security/cve/CVE-2026-59947.html * https://www.suse.com/security/cve/CVE-2026-59948.html * https://bugzilla.suse.com/show_bug.cgi?id=1271122 * https://bugzilla.suse.com/show_bug.cgi?id=1271129 * https://bugzilla.suse.com/show_bug.cgi?id=1271151 * https://bugzilla.suse.com/show_bug.cgi?id=1271504 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:31:41 -0000 Subject: SUSE-SU-2026:3104-1: important: Security update for python311 Message-ID: <178432030197.935.1785336088598190065@f4f3e2688bac> # Security update for python311 Announcement ID: SUSE-SU-2026:3104-1 Release Date: 2026-07-17T13:31:49Z Rating: important References: * bsc#1261969 * bsc#1262098 * bsc#1262319 * bsc#1262654 Cross-References: * CVE-2026-1502 * CVE-2026-4786 * CVE-2026-6019 * CVE-2026-6100 CVSS scores: * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues * CVE-2026-1502: CR/LF bytes not rejected by HTTP client proxy tunnel headers or host (bsc#1261969). * CVE-2026-4786: URLs containing `%action` can bypass mitigation that allows command injection via the `webbrowser.open()` API (bsc#1262319). * CVE-2026-6019: HTML parser-sensitive sequence not neutralized by `http.cookies.Morsel.js_output()` (bsc#1262654). * CVE-2026-6100: use-after-free in decompression modules when a memory allocation fails with a `MemoryError` and the decompression instance is re- used (bsc#1262098). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3104=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3104=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3104=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3104=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3104=1 ## Package List: * openSUSE Leap 15.6 (aarch64_ilp32) * libpython3_11-1_0-64bit-3.11.15-150600.3.59.3 * python311-base-64bit-debuginfo-3.11.15-150600.3.59.3 * python311-64bit-3.11.15-150600.3.59.3 * python311-base-64bit-3.11.15-150600.3.59.3 * libpython3_11-1_0-64bit-debuginfo-3.11.15-150600.3.59.3 * python311-64bit-debuginfo-3.11.15-150600.3.59.3 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * python311-doc-devhelp-3.11.15-150600.3.59.1 * python311-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-testsuite-3.11.15-150600.3.59.3 * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-testsuite-debuginfo-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 * python311-base-debuginfo-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * python311-doc-3.11.15-150600.3.59.1 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * openSUSE Leap 15.6 (x86_64) * python311-base-32bit-debuginfo-3.11.15-150600.3.59.3 * python311-base-32bit-3.11.15-150600.3.59.3 * libpython3_11-1_0-32bit-3.11.15-150600.3.59.3 * python311-32bit-debuginfo-3.11.15-150600.3.59.3 * python311-32bit-3.11.15-150600.3.59.3 * libpython3_11-1_0-32bit-debuginfo-3.11.15-150600.3.59.3 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-base-debuginfo-3.11.15-150600.3.59.3 * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-base-debuginfo-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-dbm-debuginfo-3.11.15-150600.3.59.3 * python311-dbm-3.11.15-150600.3.59.3 * python311-curses-3.11.15-150600.3.59.3 * python311-3.11.15-150600.3.59.3 * python311-debugsource-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-tk-3.11.15-150600.3.59.3 * python311-curses-debuginfo-3.11.15-150600.3.59.3 * python311-tk-debuginfo-3.11.15-150600.3.59.3 * python311-tools-3.11.15-150600.3.59.3 * python311-idle-3.11.15-150600.3.59.3 * python311-debuginfo-3.11.15-150600.3.59.3 * python311-devel-3.11.15-150600.3.59.3 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-base-debuginfo-3.11.15-150600.3.59.3 * libpython3_11-1_0-debuginfo-3.11.15-150600.3.59.3 * python311-core-debugsource-3.11.15-150600.3.59.3 * python311-base-3.11.15-150600.3.59.3 * libpython3_11-1_0-3.11.15-150600.3.59.3 ## References: * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1262654 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:31:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:31:49 -0000 Subject: SUSE-SU-2026:3103-1: moderate: Security update for wpa_supplicant Message-ID: <178432030978.935.953769371380577138@f4f3e2688bac> # Security update for wpa_supplicant Announcement ID: SUSE-SU-2026:3103-1 Release Date: 2026-07-17T13:30:13Z Rating: moderate References: * bsc#1239461 * bsc#1269892 Cross-References: * CVE-2025-24912 * CVE-2026-58374 CVSS scores: * CVE-2025-24912 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-24912 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-58374 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58374 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for wpa_supplicant fixes the following issues: * CVE-2025-24912: hostapd RADIUS authentication of wi-fi devices allows a user in between the hostapd and the RADIUS server to inject crafted RADIUS packets and force RADIUS authentications to fail (bsc#1239461). * CVE-2026-58374: missing bounds check in AP-mode Wi-Fi 7 (IEEE 802.11be) MLO association request processing allows an unauthenticated user to send a crafted management frame and cause an out-of-bounds write (bsc#1269892). * Missing network context validation for PMKSA caching https://w1.fi/security/2026-2/ * Unexpected SAE commit message contents terminating `wpa_supplicant` https://w1.fi/security/2026-3/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3103=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wpa_supplicant-2.11-150700.3.3.1 * wpa_supplicant-debuginfo-2.11-150700.3.3.1 * wpa_supplicant-debugsource-2.11-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-24912.html * https://www.suse.com/security/cve/CVE-2026-58374.html * https://bugzilla.suse.com/show_bug.cgi?id=1239461 * https://bugzilla.suse.com/show_bug.cgi?id=1269892 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Jul 17 20:32:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 17 Jul 2026 20:32:06 -0000 Subject: SUSE-SU-2026:3102-1: important: Security update for go1.26-openssl Message-ID: <178432032686.935.13355203260652050741@f4f3e2688bac> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:3102-1 Release Date: 2026-07-17T13:10:42Z Rating: important References: * bsc#1245878 * bsc#1255111 * bsc#1264395 * bsc#1267442 * bsc#1267444 * bsc#1267450 * bsc#1271014 * bsc#1271015 * jsc#PED-1962 * jsc#SLE-18320 Cross-References: * CVE-2026-27145 * CVE-2026-39822 * CVE-2026-42504 * CVE-2026-42505 * CVE-2026-42507 CVSS scores: * CVE-2026-27145 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27145 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-27145 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-27145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39822 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-39822 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42504 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42504 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-42504 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42505 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42505 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42507 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42507 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42507 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N Affected Products: * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities, contains two features and has three security fixes can now be installed. ## Description: This update for go1.26-openssl fixes the following issues * Update to version go1.26.5 (bsc#1255111). * CVE-2026-27145: crypto/x509: split candidate hostname only once (bsc#1267450). * CVE-2026-39822: os: Root escape via symlink plus trailing slash (bsc#1271014). * CVE-2026-42504: mime: quadratic complexity in WordDecoder.DecodeHeader (bsc#1267442). * CVE-2026-42505: crypto/tls: omit PSK in ECH outer client hello (bsc#1271015). * CVE-2026-42507: net/textproto: arbitrary input are included in errors without any escaping (bsc#1267444). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3102=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-3102=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3102=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3102=1 ## Package List: * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * go1.26-openssl-race-1.26.5-150600.13.9.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.5-150600.13.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * go1.26-openssl-race-1.26.5-150600.13.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * go1.26-openssl-doc-1.26.5-150600.13.9.1 * go1.26-openssl-1.26.5-150600.13.9.1 * go1.26-openssl-race-1.26.5-150600.13.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27145.html * https://www.suse.com/security/cve/CVE-2026-39822.html * https://www.suse.com/security/cve/CVE-2026-42504.html * https://www.suse.com/security/cve/CVE-2026-42505.html * https://www.suse.com/security/cve/CVE-2026-42507.html * https://bugzilla.suse.com/show_bug.cgi?id=1245878 * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1264395 * https://bugzilla.suse.com/show_bug.cgi?id=1267442 * https://bugzilla.suse.com/show_bug.cgi?id=1267444 * https://bugzilla.suse.com/show_bug.cgi?id=1267450 * https://bugzilla.suse.com/show_bug.cgi?id=1271014 * https://bugzilla.suse.com/show_bug.cgi?id=1271015 * https://jira.suse.com/browse/PED-1962 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: